DSA-2022-297: Dell Command | Configure Security Update for Multiple Vulnerabilities
Résumé: Dell Command | Configure remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.
Cet article concerne
Cet article ne concerne pas
Cet article n’est associé à aucun produit spécifique.
Toutes les versions du produit ne sont pas identifiées dans cet article.
Impact
High
Détails
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-34457 | Dell Command | Configure versions before 4.9.0 contain an Improper Access Control vulnerability. A local low-privileged attacker may potentially exploit this vulnerability, leading to the escalation of privilege. This vulnerability is considered critical as it allows a nonadministrator to modify files inside the installed directory and make the application unavailable for all users. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Third-party Component | CVES | More information |
| OpenSSL (3.0.0) | CVE-2022-3602 | https://nvd.nist.gov/vuln/detail/CVE-2022-3602 |
| CVE-2022-3786 | https://nvd.nist.gov/vuln/detail/CVE-2022-3786 |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-34457 | Dell Command | Configure versions before 4.9.0 contain an Improper Access Control vulnerability. A local low-privileged attacker may potentially exploit this vulnerability, leading to the escalation of privilege. This vulnerability is considered critical as it allows a nonadministrator to modify files inside the installed directory and make the application unavailable for all users. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Third-party Component | CVES | More information |
| OpenSSL (3.0.0) | CVE-2022-3602 | https://nvd.nist.gov/vuln/detail/CVE-2022-3602 |
| CVE-2022-3786 | https://nvd.nist.gov/vuln/detail/CVE-2022-3786 |
Produits concernés et mesure corrective
| CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
| CVE-2022-3602 | Dell Command | Configure | Versions before 4.9.0 | 4.9.0 | https://www.dell.com/support/home/drivers/driversdetails?driverid=0H64D |
| CVE-2022-3786 | ||||
| CVE-2022-34457 |
| CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
| CVE-2022-3602 | Dell Command | Configure | Versions before 4.9.0 | 4.9.0 | https://www.dell.com/support/home/drivers/driversdetails?driverid=0H64D |
| CVE-2022-3786 | ||||
| CVE-2022-34457 |
Historique des révisions
| Revision | Date | Description |
| 1.0 | 2022-11-22 | Initial Release |
Remerciements
CVE-2022-34457: Dell Technologies would like to thank Pwni for reporting this issue.
Informations connexes
Mention légale
Produits concernés
Dell Command | Configure, Product Security InformationPropriétés de l’article
Numéro d’article: 000205633
Type d’article: Dell Security Advisory
Dernière modification: 22 Nov 2022
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.