VYPR
High severity7.8NVD Advisory· Published Feb 7, 2019· Updated Jun 17, 2026

CVE-2019-3704

CVE-2019-3704

Description

VNX Control Station in Dell EMC VNX2 OE for File versions prior to 8.1.9.236 contains OS command injection vulnerability. Due to inadequate restriction configured in sudores, a local authenticated malicious user could potentially execute arbitrary OS commands as root by exploiting this vulnerability.

Affected products

3
  • cpe:2.3:o:dell:emc_vnx2_firmware:*:*:*:*:*:*:*:*
    Range: <8.1.9.217
  • Range: <8.1.9.236
  • Dell EMC/VNX Control Station in Dell EMC VNX2 OE for Filev5
    Range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.