Improper Access Control in Dell Repository Manager Installation Module
CVE-2023-44282

6.7MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
16 November 2023

What is CVE-2023-44282?

Dell Repository Manager prior to version 3.4.4 contains an Improper Access Control vulnerability. This flaw, located in the installation module, allows a local low-privileged attacker to potentially exploit the system to gain escalated privileges. Such vulnerabilities can lead to unauthorized access to sensitive information and control over critical system functions, emphasizing the need for timely updates and robust security measures.

Affected Version(s)

Dell Repository Manager (DRM) Versions prior to 3.4.4

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.