DSA-2025-151: Security Update for Dell Trusted Device for Multiple Vulnerabilities
Summary: Dell Trusted Device remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Medium
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-29983 |
Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
6.7 |
|
|
CVE-2025-29984 |
Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
6.7 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-29983 |
Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
6.7 |
|
|
CVE-2025-29984 |
Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
6.7 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Release Date |
Link |
|
Dell Trusted Device |
Versions prior to 7.0.3.0 |
Version 7.0.3.0 or later |
04/02/2025 |
|
Product |
Affected Versions |
Remediated Versions |
Release Date |
Link |
|
Dell Trusted Device |
Versions prior to 7.0.3.0 |
Version 7.0.3.0 or later |
04/02/2025 |
Workarounds & Mitigations
|
CVE ID |
Workaround and Mitigation |
|
CVE-2025-29983 |
Save data only to a known safe path or the default path. |
|
CVE-2025-29984 |
Install only to the default installation path. |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-04-14 |
Initial Release |
Acknowledgements
CVE-2025-29983, CVE-2025-29984: Dell Technologies would like to thank falconCorrup for reporting these issues.