DSA-2023-340: Security Update for Dell Rugged Control Center Vulnerabilities
Summary: Dell Rugged Control Center remediation is available for multiple improper access control vulnerabilities that could be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
High
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-39256 | Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder during product installation and upgrade, leading to privilege escalation on the system. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| CVE-2023-39257 | Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading to privilege escalation on the system. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-39256 | Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder during product installation and upgrade, leading to privilege escalation on the system. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| CVE-2023-39257 | Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading to privilege escalation on the system. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Affected Products & Remediation
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2023-39256, CVE-2023-39257 | Dell Rugged Control Center | Versions prior to 4.7 | Version 4.7 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4M3T2 |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2023-39256, CVE-2023-39257 | Dell Rugged Control Center | Versions prior to 4.7 | Version 4.7 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4M3T2 |
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-11-30 | Initial Release |
| 2.0 | 2023-12-04 | Updated for enhanced presentation with no changes to content. |
Related Information
Legal Disclaimer
Affected Products
Rugged Control CenterArticle Properties
Article Number: 000217705
Article Type: Dell Security Advisory
Last Modified: 04 Dec 2023
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.