Path Traversal Vulnerability in Dell GeoDrive Software
CVE-2022-33937

7.1HIGH

Key Information:

Vendor
Dell
Status
Vendor
CVE Published:
22 September 2022

Summary

Dell GeoDrive versions 1.0 through 2.2 are affected by a Path Traversal vulnerability within the reporting function. This issue allows a local attacker with low privileges to exploit the flaw, potentially gaining unauthorized access to delete files on the server filesystem. The vulnerability can be leveraged to execute operations with the privileges of the GeoDrive service, specifically NT AUTHORITY\SYSTEM, thereby posing serious risks to data integrity and security.

Affected Version(s)

GeoDrive < 2.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.