CVE-2019-3704: Dell Emc VNX2 Firmware

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

VNX Control Station in Dell EMC VNX2 OE for File versions prior to 8.1.9.236 contains OS command injection vulnerability. Due to inadequate restriction configured in sudores, a local authenticated malicious user could potentially execute arbitrary OS commands as root by exploiting this vulnerability.

Affected products

  • Dell Emc VNX2 Firmware: before 8.1.9.217 (fixed in 8.1.9.217)

Published 2019-02-07. Last modified 2026-06-17.