PT-2023-6748 · Dell · Dell Command | Monitor
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Command | Monitor versions prior to 10.9
Description
The issue is related to inadequate access control in the Dell Command | Monitor software, which can be exploited to delete arbitrary files. A locally authenticated malicious user may potentially exploit this vulnerability, leading to arbitrary folder deletion during uninstallation.
Recommendations
For versions prior to 10.9, update to version 10.9 or later to resolve the arbitrary folder delete vulnerability. As a temporary workaround, consider restricting access to the uninstallation process to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dell Command | Monitor