Hard-Coded Credential Vulnerability in Dell ELab-Navigator Software
CVE-2023-44296
5.5MEDIUM
Summary
The Dell ELab-Navigator software, version 3.1.9, contains a hard-coded credential vulnerability that allows local attackers to gain unauthorized access to sensitive data. This flaw could potentially lead to the exposure of confidential user information and may significantly compromise the integrity of the system. It is crucial for users to implement the necessary updates as detailed in the vendor's security advisory to safeguard against such threats.
Affected Version(s)
Mobility - E-Lab Navigator Versions 3.1.8 and 3.1.9
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
testingforbugs00