Improper Access Control in Dell Power Manager Affects User Privileges
CVE-2023-28051

7.8HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
7 April 2023

Summary

Dell Power Manager versions 3.10 and earlier are susceptible to an improper access control vulnerability. This flaw could be exploited by low-privileged attackers, enabling them to gain elevated privileges within the system. Users are advised to update to the latest version to mitigate this risk.

Affected Version(s)

Dell Power Manager (DPM) Versions 3.10 and prior

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.