PT-2022-6159 · Dell · Dell Geodrive

Published

2022-09-22

·

Updated

2022-10-14

·

CVE-2022-33937

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell GeoDrive versions 1.0 through 2.2
Description The issue concerns a Path Traversal Vulnerability in the reporting function of Dell GeoDrive. This vulnerability could allow a local, low-privileged attacker to gain unauthorized delete access to files stored on the server filesystem with the privileges of the GeoDrive service, which has NT AUTHORITYSYSTEM privileges. The vulnerability exists due to incorrect restriction of the path name to a directory with limited access, potentially allowing an attacker to exploit it and gain unauthorized access to delete files.
Recommendations For Dell GeoDrive versions 1.0 through 2.2, consider restricting access to the reporting function until a patch is available. As a temporary workaround, limit the privileges of the GeoDrive service to minimize potential damage from exploitation. Avoid using the vulnerable reporting function in Dell GeoDrive until the issue is resolved.

Fix

Path traversal

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00256
CVE-2022-33937

Affected Products

Dell Geodrive