← Retour
CVE-2026-74770
high
CVSS 8.8
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Résumé
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-74770** a été découverte dans dell.
L'exploitation peut entraîner la prise de contrôle totale du système. Score CVSS : 8.8/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « dell CVE-2026-74770 » sur le site de l'éditeur.
CVE-2026-74770 (dell) — CWE-78 / CVSS v3 8.8
Vecteur d'attaque : distant (réseau) / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
この脆弱性はOSコマンドインジェクションです。
📍 Périmètre concerné
Dell PowerProtect Oneのバージョン20.1.0.0およびそれ以前
🔥 Gravité
リモートの低権限攻撃者がコード実行を行う可能性があります。
🔧 Comment corriger
影響を受けるバージョンを更新することで修正できます。
🛡️ Contournement
情報なし
🔍 Détection
情報なし