PT-2023-6497 · Dell · Dell Common Event Enabler

Hamdi Aka Falconcorruption

·

Published

2023-09-29

·

Updated

2023-10-03

·

CVE-2023-32477

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Common Event Enabler versions 8.9.8.2 and prior
Description The issue is related to an improper access control vulnerability in the Dell Common Event Enabler module, which is part of the Dell OpenManage Client Instrumentation (OMCI) utility. This vulnerability can be exploited by a local low-privileged malicious user to gain elevated privileges.
Recommendations For Dell Common Event Enabler versions 8.9.8.2 and prior, consider restricting access to the vulnerable module to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2023-07243
CVE-2023-32477

Affected Products

Dell Common Event Enabler