Hard-Coded Credential Vulnerability in Dell ELab-Navigator Software
CVE-2023-44296

5.5MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
16 November 2023

Summary

The Dell ELab-Navigator software, version 3.1.9, contains a hard-coded credential vulnerability that allows local attackers to gain unauthorized access to sensitive data. This flaw could potentially lead to the exposure of confidential user information and may significantly compromise the integrity of the system. It is crucial for users to implement the necessary updates as detailed in the vendor's security advisory to safeguard against such threats.

Affected Version(s)

Mobility - E-Lab Navigator Versions 3.1.8 and 3.1.9

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

testingforbugs00
.