DSA-2023-371: Dell Rugged Control Center Security Update for an Improper Access Control Vulnerability
Summary: Dell Rugged Control Center remediation is available for an improper access control vulnerability that could be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Medium
Details
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Affected Products & Remediation
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center | Versions prior to 4.7 | Version 4.7 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4M3T2 |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center | Versions prior to 4.7 | Version 4.7 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4M3T2 |
Workarounds & Mitigations
Dell Rugged Control Center UI would provide an SHA-256 hash of the Policy File to the administrator, which can be used to cross-verify the legitimacy of the policy file after transfer.
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-11-30 | Initial Release |
Related Information
Legal Disclaimer
Affected Products
Rugged Control CenterArticle Properties
Article Number: 000218066
Article Type: Dell Security Advisory
Last Modified: 30 Nov 2023
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.