CVE-2024-0170
Dell
CVE-2024-0170: Dell Unity OS Command Injection Vulnerability. This flaw allows an authenticated attacker to inject commands, potentially gaining root access.
CVE-2024-0170 affects Dell Unity systems before version 5.4, presenting a significant security risk due to an OS Command Injection Vulnerability within the svc_cava utility. Exploiting this vulnerability allows an authenticated attacker to bypass the restricted shell and execute arbitrary operating system commands with root privileges. The CVSS score is 7.8 indicating a high severity threat. Although the SVRS score of 70 does not signify immediate action, the 'In The Wild' tag indicates active exploitation, requiring vigilance. Successful exploitation grants complete control over the affected system, potentially leading to data breaches, system compromise, and denial of service.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.