PT-2024-19416 · Dell · Idrac Service Module

CVE-2024-22428

·

Published

2024-01-15

·

Updated

2024-01-23

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell iDRAC Service Module versions 5.2.0.0 and prior
Description The issue is related to Incorrect Default Permissions, which may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system.
Recommendations For versions 5.2.0.0 and prior, upgrade to a newer version at the earliest opportunity to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-22428

Affected Products

Idrac Service Module