PT-2024-5610 · Dell · Dell Inventory Collector
Jony_Juice
·
Published
2024-06-24
·
Updated
2024-08-13
·
CVE-2024-37129
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Inventory Collector versions prior to 12.3.0.6
Description
The issue is related to incorrect restriction of a directory path with limited access. Exploitation of this issue may allow an attacker to execute arbitrary code. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.
Recommendations
For versions prior to 12.3.0.6, update to version 12.3.0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive directories to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Inventory Collector