PT-2023-28690 · Dell · Dell Command Configure

Published

2023-11-23

·

Updated

2023-11-30

·

CVE-2023-43086

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Command | Configure versions prior to 4.11.0
Description The issue is related to improper access control, allowing a local malicious user to potentially modify files inside the installation folder during an application upgrade. This could lead to privilege escalation.
Recommendations For versions prior to 4.11.0, update to version 4.11.0 or later to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-43086

Affected Products

Dell Command Configure