DSA-2022-297: Dell Command | Configure Security Update for Multiple Vulnerabilities
Zusammenfassung: Dell Command | Configure remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.
Dieser Artikel gilt für
Dieser Artikel gilt nicht für
Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden.
In diesem Artikel werden nicht alle Produktversionen aufgeführt.
Auswirkungen
High
Details
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-34457 | Dell Command | Configure versions before 4.9.0 contain an Improper Access Control vulnerability. A local low-privileged attacker may potentially exploit this vulnerability, leading to the escalation of privilege. This vulnerability is considered critical as it allows a nonadministrator to modify files inside the installed directory and make the application unavailable for all users. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Third-party Component | CVES | More information |
| OpenSSL (3.0.0) | CVE-2022-3602 | https://nvd.nist.gov/vuln/detail/CVE-2022-3602 |
| CVE-2022-3786 | https://nvd.nist.gov/vuln/detail/CVE-2022-3786 |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-34457 | Dell Command | Configure versions before 4.9.0 contain an Improper Access Control vulnerability. A local low-privileged attacker may potentially exploit this vulnerability, leading to the escalation of privilege. This vulnerability is considered critical as it allows a nonadministrator to modify files inside the installed directory and make the application unavailable for all users. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Third-party Component | CVES | More information |
| OpenSSL (3.0.0) | CVE-2022-3602 | https://nvd.nist.gov/vuln/detail/CVE-2022-3602 |
| CVE-2022-3786 | https://nvd.nist.gov/vuln/detail/CVE-2022-3786 |
Betroffene Produkte und Korrektur
| CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
| CVE-2022-3602 | Dell Command | Configure | Versions before 4.9.0 | 4.9.0 | https://www.dell.com/support/home/drivers/driversdetails?driverid=0H64D |
| CVE-2022-3786 | ||||
| CVE-2022-34457 |
| CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
| CVE-2022-3602 | Dell Command | Configure | Versions before 4.9.0 | 4.9.0 | https://www.dell.com/support/home/drivers/driversdetails?driverid=0H64D |
| CVE-2022-3786 | ||||
| CVE-2022-34457 |
Revisionsverlauf
| Revision | Date | Description |
| 1.0 | 2022-11-22 | Initial Release |
Danksagung
CVE-2022-34457: Dell Technologies would like to thank Pwni for reporting this issue.
Zugehörige Informationen
Rechtlicher Hinweis
Betroffene Produkte
Dell Command | Configure, Product Security InformationArtikeleigenschaften
Artikelnummer: 000205633
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 22 Nov. 2022
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.