DSA-2023-371: Dell Rugged Control Center Security Update for an Improper Access Control Vulnerability
Résumé: Dell Rugged Control Center remediation is available for an improper access control vulnerability that could be exploited by malicious users to compromise the affected system.
Cet article concerne
Cet article ne concerne pas
Cet article n’est associé à aucun produit spécifique.
Toutes les versions du produit ne sont pas identifiées dans cet article.
Impact
Medium
Détails
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Produits concernés et mesure corrective
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center | Versions prior to 4.7 | Version 4.7 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4M3T2 |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-43089 | Dell Rugged Control Center | Versions prior to 4.7 | Version 4.7 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4M3T2 |
Solutions de contournement et mesures d’atténuation
Dell Rugged Control Center UI would provide an SHA-256 hash of the Policy File to the administrator, which can be used to cross-verify the legitimacy of the policy file after transfer.
Historique des révisions
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-11-30 | Initial Release |
Informations connexes
Mention légale
Produits concernés
Rugged Control CenterPropriétés de l’article
Numéro d’article: 000218066
Type d’article: Dell Security Advisory
Dernière modification: 30 nov. 2023
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.