PT-2023-6748 · Dell · Dell Command | Monitor

Ycdxsb

·

Published

2023-02-08

·

Updated

2023-02-17

·

CVE-2023-24573

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Command | Monitor versions prior to 10.9
Description The issue is related to inadequate access control in the Dell Command | Monitor software, which can be exploited to delete arbitrary files. A locally authenticated malicious user may potentially exploit this vulnerability, leading to arbitrary folder deletion during uninstallation.
Recommendations For versions prior to 10.9, update to version 10.9 or later to resolve the arbitrary folder delete vulnerability. As a temporary workaround, consider restricting access to the uninstallation process to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2023-07535
CVE-2023-24573

Affected Products

Dell Command | Monitor