Dell Repository Manager Vulnerability Allows Unauthorized File Access
CVE-2024-28976

7.8HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
24 April 2024

Summary

Dell Repository Manager, prior to version 3.4.5, is susceptible to a path traversal vulnerability in its API module. A local attacker with limited privileges can exploit this weakness to gain unauthorized write access to server files, leveraging the permissions of the running web application. This vulnerability poses substantial risks to the confidentiality and integrity of data stored on the server filesystem.

Affected Version(s)

Dell Repository Manager (DRM) < 3.4.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank Jakub Brzozowski (redfr0g) for reporting this issue.
.