DSA-2023-075: Dell Power Manager Security Update for an Improper Authorization Vulnerability
Resumen: Dell Power Manager remediation is available for an Improper Authorization vulnerability that could be exploited by malicious users to compromise the affected system.
Este artículo se aplica a
Este artículo no se aplica a
Este artículo no está vinculado a ningún producto específico.
No se identifican todas las versiones del producto en este artículo.
Impacto
High
Detalles
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
| CVE-2023-25543 | Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on the system. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H See NVD (http://nvd.nist.gov/) |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
| CVE-2023-25543 | Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on the system. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H See NVD (http://nvd.nist.gov/) |
Corrección y productos afectados
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2023-25543 | Dell Power Manager | Versions prior to 3.14 |
3.14 | https://www.dell.com/support/home/drivers/driversdetails?driverid=8678v |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2023-25543 | Dell Power Manager | Versions prior to 3.14 |
3.14 | https://www.dell.com/support/home/drivers/driversdetails?driverid=8678v |
Soluciones alternativas y mitigaciones
None.
Historial de revisiones
| Revision | Date | Description |
| 1.0 | 2023-04-04 | Initial Release |
Reconocimientos
CVE-2023-25543: Dell Technologies would like to thank Cedric Van Bockhaven for reporting this issue.
Información relacionada
Descargo de responsabilidad
Productos afectados
Dell Power Manager, Product Security InformationPropiedades del artículo
Número del artículo: 000209464
Tipo de artículo: Dell Security Advisory
Última modificación: 11 abr. 2023
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.