Improper Access Control in Dell Repository Manager Installation Module
CVE-2023-44282

6.7MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
16 November 2023

Summary

Dell Repository Manager prior to version 3.4.4 contains an Improper Access Control vulnerability. This flaw, located in the installation module, allows a local low-privileged attacker to potentially exploit the system to gain escalated privileges. Such vulnerabilities can lead to unauthorized access to sensitive information and control over critical system functions, emphasizing the need for timely updates and robust security measures.

Affected Version(s)

Dell Repository Manager (DRM) Versions prior to 3.4.4

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.