PT-2022-6159 · Dell · Dell Geodrive
Published
2022-09-22
·
Updated
2022-10-14
·
CVE-2022-33937
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell GeoDrive versions 1.0 through 2.2
Description
The issue concerns a Path Traversal Vulnerability in the reporting function of Dell GeoDrive. This vulnerability could allow a local, low-privileged attacker to gain unauthorized delete access to files stored on the server filesystem with the privileges of the GeoDrive service, which has NT AUTHORITYSYSTEM privileges. The vulnerability exists due to incorrect restriction of the path name to a directory with limited access, potentially allowing an attacker to exploit it and gain unauthorized access to delete files.
Recommendations
For Dell GeoDrive versions 1.0 through 2.2, consider restricting access to the reporting function until a patch is available.
As a temporary workaround, limit the privileges of the GeoDrive service to minimize potential damage from exploitation.
Avoid using the vulnerable reporting function in Dell GeoDrive until the issue is resolved.
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Geodrive