DSA-2026-106: Security Update for Dell Command | Intel vPro Out of Band for an Uncontrolled Search Path Element Vulnerability
Summary: Dell Command | Intel vPro Out of Band remediation is available for Uncontrolled Search Path Element vulnerability that could be exploited by malicious users to compromise the affected system. ...
Impact
High
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-24502 |
Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
8.8 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-24502 |
Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
8.8 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Dell Command | Intel vPro Out of Band |
Versions prior to 4.7.0 |
Version 4.7.0 or later |
02/27/2026 |
Dell Command | Intel vPro Out of Band | Driver Details | Dell US |
|
Product |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Dell Command | Intel vPro Out of Band |
Versions prior to 4.7.0 |
Version 4.7.0 or later |
02/27/2026 |
Dell Command | Intel vPro Out of Band | Driver Details | Dell US |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2026-03-03 |
Initial Release |
Acknowledgements
Dell would like to thank Sandro Poppi for reporting this issue.