DSA-2022-201: Dell Command | Integration Suite for System Center Security Update for Arbitrary File Write Vulnerability
Resumen: Dell Command | Integration Suite for System Center contains remediation for arbitrary file write vulnerability that may be exploited by locally authenticated malicious users to compromise the affected system. ...
Este artículo se aplica a
Este artículo no se aplica a
Este artículo no está vinculado a ningún producto específico.
No se identifican todas las versiones del producto en este artículo.
Impacto
High
Detalles
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-34373 | Dell Command | Integration Suite for System Center versions before 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user may potentially exploit this vulnerability in order to perform an arbitrary write as system. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-34373 | Dell Command | Integration Suite for System Center versions before 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user may potentially exploit this vulnerability in order to perform an arbitrary write as system. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Corrección y productos afectados
| Product | Affected Versions | Updated Version | Link to Update | |
| Dell Command | Integration Suite for System Center | Versions before 6.2.0 | 6.2.0 | https://www.dell.com/support/home/en-us/drivers/DriversDetails?driverId=HY40M | |
| Product | Affected Versions | Updated Version | Link to Update | |
| Dell Command | Integration Suite for System Center | Versions before 6.2.0 | 6.2.0 | https://www.dell.com/support/home/en-us/drivers/DriversDetails?driverId=HY40M | |
Historial de revisiones
| Revision | Date | Description |
| 1.0 | 2022-07-26 | Initial Release |
Reconocimientos
Dell would like to thank Johannes Hatting for reporting this issue.
Información relacionada
Descargo de responsabilidad
Productos afectados
Dell Command | Integration Suite for Microsoft System Center, Product Security InformationPropiedades del artículo
Número del artículo: 000201877
Tipo de artículo: Dell Security Advisory
Última modificación: 12 jun 2023
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.