PT-2021-21194 · Dell · Dell Command | Update+2
Published
2021-08-09
·
Updated
2023-02-10
·
CVE-2021-36277
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.3
Description
The issue is related to an improper verification of cryptographic signatures, allowing a local authenticated malicious user to exploit the vulnerability and execute arbitrary code on the system. This can be achieved by modifying local configuration files.
Recommendations
For versions prior to 4.3, update to version 4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to configuration files that could be modified to execute arbitrary code, until a patch is applied.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alienware Update
Dell Command | Update
Dell Update