PT-2022-22165 · Dell · Dell Hybrid Client

Published

2022-10-11

·

Updated

2022-10-13

·

CVE-2022-34430

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dell Hybrid Client versions prior to 1.8
Description The issue concerns a Zip Bomb Vulnerability in the UI of Dell Hybrid Client, which could be exploited by an attacker with guest privileges, potentially leading to modification of system files.
Recommendations For versions prior to 1.8, update to version 1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the UI to minimize the risk of exploitation.

Fix

Path traversal

XML Entity Expansion

Weakness Enumeration

Related Identifiers

CVE-2022-34430

Affected Products

Dell Hybrid Client