Dell Repository Manager Vulnerability Allows Unauthorized File Access
CVE-2024-28976
7.8HIGH
Summary
Dell Repository Manager, prior to version 3.4.5, is susceptible to a path traversal vulnerability in its API module. A local attacker with limited privileges can exploit this weakness to gain unauthorized write access to server files, leveraging the permissions of the running web application. This vulnerability poses substantial risks to the confidentiality and integrity of data stored on the server filesystem.
Affected Version(s)
Dell Repository Manager (DRM) < 3.4.5
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank Jakub Brzozowski (redfr0g) for reporting this issue.