PT-2023-6748 · Dell · Dell Command | Monitor
Ycdxsb
·
Published
2023-02-08
·
Updated
2023-02-17
·
CVE-2023-24573
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Command | Monitor versions prior to 10.9
Description
The issue is related to inadequate access control in the Dell Command | Monitor software, which can be exploited to delete arbitrary files. A locally authenticated malicious user may potentially exploit this vulnerability, leading to arbitrary folder deletion during uninstallation.
Recommendations
For versions prior to 10.9, update to version 10.9 or later to resolve the arbitrary folder delete vulnerability. As a temporary workaround, consider restricting access to the uninstallation process to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Command | Monitor