PT-2024-29937 · Dell · Dell Networker

Published

2024-12-03

·

Updated

2024-12-08

·

CVE-2024-42422

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Dell NetWorker version 19.10
Description The issue is an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information disclosure.
Recommendations For Dell NetWorker version 19.10, upgrade the affected component immediately to mitigate the risk. As a temporary workaround, consider restricting access to sensitive information until the issue is resolved.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-42422

Affected Products

Dell Networker