Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malicious commands on ACM component.
| Software | From | Fixed in |
|---|---|---|
| dell / emc_integrated_data_protection_appliance | 2.0 | 2.0.x |
| dell / emc_integrated_data_protection_appliance | 2.1 | 2.1.x |
| dell / emc_integrated_data_protection_appliance | 2.2 | 2.2.x |
| dell / emc_integrated_data_protection_appliance | 2.3 | 2.3.x |
| dell / emc_integrated_data_protection_appliance | 2.4 | 2.4.x |