DSA-2023-415: Security Update for Dell Repository Manager vulnerability
Resumen: Dell Repository Manager remediation is available for Multiple Improper Access Controls Vulnerabilities that could be exploited by malicious users to compromise the affected system.
Este artículo se aplica a
Este artículo no se aplica a
Este artículo no está vinculado a ningún producto específico.
No se identifican todas las versiones del producto en este artículo.
Impacto
Medium
Detalles
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-44292 | Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges. | 6.7 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
| CVE-2023-44282 | Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges. | 6.7 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-44292 | Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges. | 6.7 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
| CVE-2023-44282 | Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges. | 6.7 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Corrección y productos afectados
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2023-44292, CVE-2023-44282 | Dell Repository Manager | Versions prior to 3.4.4 | 3.4.4 | Apply the latest Security Remediation |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2023-44292, CVE-2023-44282 | Dell Repository Manager | Versions prior to 3.4.4 | 3.4.4 | Apply the latest Security Remediation |
Historial de revisiones
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-11-07 | Initial Release |
| 2.0 | 2023-11-08 | Minor formatting editing with no changes to the information. |
| 3.0 | 2023-11-13 | Minor formatting editing with no changes to the information. |
| 4.0 | 2023-11-14 | Minor formatting editing with no changes to the information. |
| 5.0 | 2013-11-15 | Minor formatting editing with no changes to the information. |
Información relacionada
Descargo de responsabilidad
Productos afectados
Dell Repository Manager Version 2.1, Dell Repository Manager Version 2.2, Dell Repository Manager Version 1.0, Dell Repository Manager Version 1.1, Dell Repository Manager Version 1.2, Dell Repository Manager Version 1.3
, Dell Repository Manager Version 1.4, Dell Repository Manager Version 1.5, Dell Repository Manager Version 1.6, Dell Repository Manager Version 1.7, Dell Repository Manager Version 1.8, Dell Repository Manager Version 1.9, Dell Repository Manager Version 2.0
...
Propiedades del artículo
Número del artículo: 000219303
Tipo de artículo: Dell Security Advisory
Última modificación: 15 nov 2023
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.