VYPR
Unrated severityNVD Advisory· Published Oct 5, 2023· Updated Sep 19, 2024

CVE-2023-4401

CVE-2023-4401

Description

OS command injection in Dell SmartFabric Storage Software CLI 'more' command allows authenticated attackers to execute arbitrary commands as root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OS command injection in Dell SmartFabric Storage Software CLI 'more' command allows authenticated attackers to execute arbitrary commands as root.

Vulnerability

An OS command injection vulnerability exists in the more command of the Dell SmartFabric Storage Software CLI. Affected versions are v1.4.0 and prior, as identified in the Dell advisory [1]. The flaw resides in the Debian package used for upgrading the SmartFabric Storage Software VM deployed on ESXi or Linux KVM, as well as in the standalone packages for ESXi and Linux KVM [1].

Exploitation

An attacker must be authenticated (either locally or remotely) to the SmartFabric Storage Software CLI. By supplying crafted input to the more command, the attacker can inject arbitrary OS commands. The injection occurs because user-supplied data is not properly sanitized before being passed to the operating system shell.

Impact

Successful exploitation allows the attacker to execute arbitrary OS commands with root-level privileges. This results in full compromise of the affected system, including the ability to read, modify, or delete sensitive data, install malware, or pivot to other systems.

Mitigation

Dell has released version v1.4.1 which addresses this vulnerability. Users should upgrade to v1.4.1 using the appropriate package for their deployment (ESXi or Linux KVM) as detailed in the advisory [1]. No workarounds are documented; upgrading is the recommended action.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.