DSA-2023-371: Dell Rugged Control Center Security Update for an Improper Access Control Vulnerability
Resumen: Dell Rugged Control Center remediation is available for an improper access control vulnerability that could be exploited by malicious users to compromise the affected system.
Este artículo se aplica a
Este artículo no se aplica a
Este artículo no está vinculado a ningún producto específico.
No se identifican todas las versiones del producto en este artículo.
Impacto
Medium
Detalles
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Corrección y productos afectados
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center | Versions prior to 4.7 | Version 4.7 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4M3T2 |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center | Versions prior to 4.7 | Version 4.7 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4M3T2 |
Soluciones alternativas y mitigaciones
Dell Rugged Control Center UI would provide an SHA-256 hash of the Policy File to the administrator, which can be used to cross-verify the legitimacy of the policy file after transfer.
Historial de revisiones
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-11-30 | Initial Release |
Información relacionada
Descargo de responsabilidad
Productos afectados
Rugged Control CenterPropiedades del artículo
Número del artículo: 000218066
Tipo de artículo: Dell Security Advisory
Última modificación: 30 nov 2023
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.