VYPR
Unrated severityNVD Advisory· Published Oct 5, 2023· Updated Sep 19, 2024

CVE-2023-43072

CVE-2023-43072

Description

Improper access control in Dell SmartFabric Storage Software CLI allows local unauthenticated attackers to execute arbitrary shell commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper access control in Dell SmartFabric Storage Software CLI allows local unauthenticated attackers to execute arbitrary shell commands.

Vulnerability

An improper access control vulnerability exists in the CLI of Dell SmartFabric Storage Software versions v1.4.0 and prior [1]. This flaw allows a local attacker, who may not require authentication, to bypass intended access restrictions and execute arbitrary shell commands [1].

Exploitation

An attacker with local access to the system can exploit the improper access control in the CLI without needing prior authentication [1]. The exact exploitation steps are not detailed in the available references, but the vulnerability enables the attacker to execute arbitrary shell commands directly through the CLI interface.

Impact

Successful exploitation grants the attacker the ability to execute arbitrary shell commands on the affected system [1]. This can lead to full compromise of the SmartFabric Storage Software, including unauthorized access to data, modification of system configurations, and potential disruption of storage services.

Mitigation

Dell has released version v1.4.1 of SmartFabric Storage Software to address this vulnerability [1]. Users are advised to upgrade to the fixed version using the appropriate Debian package for ESXi or Linux KVM deployments [1]. No workarounds are documented in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.