PT-2022-22165 · Dell · Dell Hybrid Client

CVE-2022-34430

·

Published

2022-10-11

·

Updated

2022-10-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dell Hybrid Client versions prior to 1.8
Description The issue concerns a Zip Bomb Vulnerability in the UI of Dell Hybrid Client, which could be exploited by an attacker with guest privileges, potentially leading to modification of system files.
Recommendations For versions prior to 1.8, update to version 1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the UI to minimize the risk of exploitation.

Fix

Path traversal

XML Entity Expansion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-34430

Affected Products

Dell Hybrid Client