Uncontrolled Search Path Element Vulnerability in Dell Peripheral Manager Software
CVE-2024-22451
6.7MEDIUM
What is CVE-2024-22451?
The Dell Peripheral Manager versions 1.5.1 to 1.7.2 are susceptible to an uncontrolled search path element vulnerability. This security flaw allows attackers to preload malicious executables, which can result in arbitrary code execution on affected systems. Users are urged to apply the latest security updates to mitigate risk and protect against potential exploitation.
Affected Version(s)
Peripheral Manager 0 < 1.7.3 or later
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell Technologies would like to thank Yue Liu From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue.