Dell Repository Manager Vulnerability Allows Unauthorized File Access
CVE-2024-28976

7.8HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
24 April 2024

What is CVE-2024-28976?

Dell Repository Manager, prior to version 3.4.5, is susceptible to a path traversal vulnerability in its API module. A local attacker with limited privileges can exploit this weakness to gain unauthorized write access to server files, leveraging the permissions of the running web application. This vulnerability poses substantial risks to the confidentiality and integrity of data stored on the server filesystem.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Dell Repository Manager (DRM) < 3.4.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank Jakub Brzozowski (redfr0g) for reporting this issue.
.