U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-44277

Change History

Initial Analysis by NIST 12/27/2023 2:33:29 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:dell:apex_protection_storage:*:*:*:*:*:*:*:* versions up to (excluding) 6.2.1.110
          *cpe:2.3:a:dell:apex_protection_storage:*:*:*:*:*:*:*:* versions from (including) 7.0 up to (excluding) 7.10.1.15
          *cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:virtual:*:*:* versions up to (excluding) 6.2.1.110
          *cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:virtual:*:*:* versions from (including) 7.0 up to (excluding) 7.12.0.0
          *cpe:2.3:a:dell:powerprotect_data_domain_management_center:*:*:*:*:*:*:*:* versions up to (excluding) 6.2.1.110
          *cpe:2.3:a:dell:powerprotect_data_domain_management_center:*:*:*:*:*:*:*:* versions from (including) 7.0 up to (excluding) 7.13.0.10
          *cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:*:*:*:* versions up to (excluding) 6.2.1.110
          *cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:*:*:*:* versions from (including) 7.0 up to (excluding) 7.12.0.0
          *cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:lts2022:*:*:* versions from (including) 7.7 up to (excluding) 7.7.5.25
          *cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:lts2023:*:*:* versions from (including) 7.10 up to (excluding) 7.10.1.15
          *cpe:2.3:o:dell:powerprotect_data_domain_management_center:*:*:*:*:lts2022:*:*:* versions from (including) 7.7 up to (excluding) 7.7.5.25
          *cpe:2.3:o:dell:powerprotect_data_domain_management_center:*:*:*:*:lts2023:*:*:* versions from (including) 7.10 up to (excluding) 7.10.1.15
     OR
          cpe:2.3:h:dell:dd3300:-:*:*:*:*:*:*:*
          cpe:2.3:h:dell:dd6400:-:*:*:*:*:*:*:*
          cpe:2.3:h:dell:dd6900:-:*:*:*:*:*:*:*
          cpe:2.3:h:dell:dd9400:-:*:*:*:*:*:*:*
          cpe:2.3:h:dell:dd9900:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:dell:powerprotect_data_protection:*:*:*:*:*:*:*:* versions up to (excluding) 2.7.6
     OR
          cpe:2.3:h:dell:dp4400:-:*:*:*:*:*:*:*
          cpe:2.3:h:dell:dp5900:-:*:*:*:*:*:*:*
Added CVSS V3.1

								
							
							
						
NIST AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
NIST CWE-78
Changed Reference Type
https://www.dell.com/support/kbdoc/en-us/000220264/dsa-2023-412-dell-technologies-powerprotect-security-update-for-multiple-security-vulnerabilities No Types Assigned
https://www.dell.com/support/kbdoc/en-us/000220264/dsa-2023-412-dell-technologies-powerprotect-security-update-for-multiple-security-vulnerabilities Vendor Advisory