Improper Link Resolution Issue in Dell Inventory Collector Client
CVE-2024-47480
7.8HIGH
Summary
The vulnerability identified as CVE-2024-47480 affects Dell Inventory Collector Client versions prior to 12.7.0 and stems from an Improper Link Resolution Before File Access. This security flaw can be exploited by low-privilege attackers who have local access to the system. If successfully exploited, it may lead to Elevation of Privileges, granting unauthorized access to the file system, thereby compromising the integrity and confidentiality of sensitive data. To mitigate this vulnerability, it is crucial for users to update their Dell Inventory Collector Client to version 12.7.0 or later, as outlined in Dell's advisory.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published