DSA-2024-488: Security Update for Dell NativeEdge Multiple Vulnerabilities
Summary: Dell NativeEdge remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|---|---|---|---|
| CVE-2024-47978 |
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.8 |
|
| CVE-2024-53291 |
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
7.5 |
|
| CVE-2024-52543 |
Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |
6.5 |
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|---|---|---|---|
| CVE-2024-47978 |
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.8 |
|
| CVE-2024-53291 |
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
7.5 |
|
| CVE-2024-52543 |
Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |
6.5 |
Affected Products & Remediation
| Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|---|
| NativeEdge |
NativeEdge Orchestrator |
Version prior to 2.1.0.0 |
Version 2.2.0.0 |
| Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|---|
| NativeEdge |
NativeEdge Orchestrator |
Version prior to 2.1.0.0 |
Version 2.2.0.0 |
Revision History
|
Revision |
Date |
Description |
|---|---|---|
|
1.0 |
2024-12-19 |
Initial Release |
|
2.0 |
2024-12-25 |
Updated the "CVSS Vector String" under the "Details" section for CVE-2024-52543 |