Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and Dell Data Lakehouse versions prior to 1.2.0.0 contain an Improper Link Resolution Before File Access vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to execute arbitrary code on the system.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-36978 Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and Dell Data Lakehouse versions prior to 1.2.0.0 contain an Improper Link Resolution Before File Access vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to execute arbitrary code on the system.
Fixes

Solution

No solution given by the vendor.


Workaround

For remediation for PowerFlex Manager versions prior to 4.6.1 (RCMs prior to 3.7.6.0/3.8.1.0 or ICs prior to 46.376.00/46.381.00), reference KB Article 000231116 Mitigation for Powerflex Manager CVE-2024-37143 https://www.dell.com/support/kbdoc/en-us/000231116  (customer login required).

History

Fri, 23 Jan 2026 01:30:00 +0900

Type Values Removed Values Added
First Time appeared Dell
Dell data Lakehouse
Dell insightiq
Dell powerflex Appliance Intelligent Catalog
Dell powerflex Manager
Dell powerflex Rack Release Certification Matrix
CPEs cpe:2.3:a:dell:data_lakehouse:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:insightiq:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerflex_appliance_intelligent_catalog:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerflex_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerflex_rack_release_certification_matrix:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell data Lakehouse
Dell insightiq
Dell powerflex Appliance Intelligent Catalog
Dell powerflex Manager
Dell powerflex Rack Release Certification Matrix

Wed, 16 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.01158}

epss

{'score': 0.01467}


Thu, 12 Dec 2024 03:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Dec 2024 12:00:00 +0900

Type Values Removed Values Added
Description Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and Dell Data Lakehouse versions prior to 1.2.0.0 contain an Improper Link Resolution Before File Access vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to execute arbitrary code on the system.
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-12-11T17:16:29.723Z

Reserved: 2024-06-03T12:10:32.206Z

Link: CVE-2024-37143

cve-icon Vulnrichment

Updated: 2024-12-11T17:15:52.562Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-10T03:15:05.573

Modified: 2026-01-22T16:24:36.057

Link: CVE-2024-37143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses