DSA-2022-201: Dell Command | Integration Suite for System Center Security Update for Arbitrary File Write Vulnerability
Resumo: Dell Command | Integration Suite for System Center contains remediation for arbitrary file write vulnerability that may be exploited by locally authenticated malicious users to compromise the affected system. ...
Este artigo aplica-se a
Este artigo não se aplica a
Este artigo não está vinculado a nenhum produto específico.
Nem todas as versões do produto estão identificadas neste artigo.
Impacto
High
Dados
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-34373 | Dell Command | Integration Suite for System Center versions before 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user may potentially exploit this vulnerability in order to perform an arbitrary write as system. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-34373 | Dell Command | Integration Suite for System Center versions before 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user may potentially exploit this vulnerability in order to perform an arbitrary write as system. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Produtos afetados e soluções
| Product | Affected Versions | Updated Version | Link to Update | |
| Dell Command | Integration Suite for System Center | Versions before 6.2.0 | 6.2.0 | https://www.dell.com/support/home/en-us/drivers/DriversDetails?driverId=HY40M | |
| Product | Affected Versions | Updated Version | Link to Update | |
| Dell Command | Integration Suite for System Center | Versions before 6.2.0 | 6.2.0 | https://www.dell.com/support/home/en-us/drivers/DriversDetails?driverId=HY40M | |
Histórico de revisão
| Revision | Date | Description |
| 1.0 | 2022-07-26 | Initial Release |
Agradecimentos
Dell would like to thank Johannes Hatting for reporting this issue.
Informações relacionadas
Aviso de isenção legal
Produtos afetados
Dell Command | Integration Suite for Microsoft System Center, Product Security InformationPropriedades do artigo
Número do artigo: 000201877
Tipo de artigo: Dell Security Advisory
Último modificado: 12 jun. 2023
Encontre as respostas de outros usuários da Dell para suas perguntas.
Serviços de suporte
Verifique se o dispositivo está coberto pelos serviços de suporte.