Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000207513


DSA-2023-017: Dell Repository Manager Security Update for an Improper Privilege Management Vulnerability

Summary: Dell Repository Manager remediation is available for an improper privilege management vulnerability that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2023-22576 Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary executable on the operating system with high privileges using the existing vulnerability in operating system. Exploitation may lead to unavailability of the service.
 
7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2023-22576 Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary executable on the operating system with high privileges using the existing vulnerability in operating system. Exploitation may lead to unavailability of the service.
 
7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs
Addressed  
Product Affected Versions Remediated Versions Link
CVE-2023-22576 Dell Repository Manager (DRM) 3.4.2 and earlier  3.4.3 Link to Download
CVEs
Addressed  
Product Affected Versions Remediated Versions Link
CVE-2023-22576 Dell Repository Manager (DRM) 3.4.2 and earlier  3.4.3 Link to Download

Workarounds and Mitigations

CVE ID Workaround and Mitigation
CVE-2023-22576 Installing DRM in default path, such as C:\Program Files, does not enable this vulnerability.

Acknowledgements

Dell would like to thank Marius Gabriel Mihai for reporting this issue.

Revision History

RevisionDateDescription
1.02023-01-13Initial Release
2.02023-01-27Update
3.02023-07-10Updated for enhanced presentation with no changes to content  
 

 

 

Related Information


Article Properties


Affected Product

Dell EMC Repository Manager 3.0, Dell EMC Repository Manager 3.0.1, Dell EMC Repository Manager 3.1, Dell EMC Repository Manager 3.2

Last Published Date

10 Jul 2023

Article Type

Dell Security Advisory