High
Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
CVE-2022-34457 | Dell Command | Configure versions before 4.9.0 contain an Improper Access Control vulnerability. A local low-privileged attacker may potentially exploit this vulnerability, leading to the escalation of privilege. This vulnerability is considered critical as it allows a nonadministrator to modify files inside the installed directory and make the application unavailable for all users. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Third-party Component | CVES | More information |
OpenSSL (3.0.0) | CVE-2022-3602 | https://nvd.nist.gov/vuln/detail/CVE-2022-3602 |
CVE-2022-3786 | https://nvd.nist.gov/vuln/detail/CVE-2022-3786 |
Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
CVE-2022-34457 | Dell Command | Configure versions before 4.9.0 contain an Improper Access Control vulnerability. A local low-privileged attacker may potentially exploit this vulnerability, leading to the escalation of privilege. This vulnerability is considered critical as it allows a nonadministrator to modify files inside the installed directory and make the application unavailable for all users. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Third-party Component | CVES | More information |
OpenSSL (3.0.0) | CVE-2022-3602 | https://nvd.nist.gov/vuln/detail/CVE-2022-3602 |
CVE-2022-3786 | https://nvd.nist.gov/vuln/detail/CVE-2022-3786 |
CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
CVE-2022-3602 | Dell Command | Configure | Versions before 4.9.0 | 4.9.0 | https://www.dell.com/support/home/drivers/driversdetails?driverid=0H64D |
CVE-2022-3786 | ||||
CVE-2022-34457 |
CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
CVE-2022-3602 | Dell Command | Configure | Versions before 4.9.0 | 4.9.0 | https://www.dell.com/support/home/drivers/driversdetails?driverid=0H64D |
CVE-2022-3786 | ||||
CVE-2022-34457 |
Revision | Date | Description |
1.0 | 2022-11-22 | Initial Release |
CVE-2022-34457: Dell Technologies would like to thank Pwni for reporting this issue.