DSA-2024-073: Security Update for Dell Mobility - E-Lab Navigator Vulnerabilities
Résumé: Dell Mobility - E-Lab Navigator remediation is available for insecure direct object vulnerability that could be exploited by malicious users to compromise the affected system.
Cet article concerne
Cet article ne concerne pas
Cet article n’est associé à aucun produit spécifique.
Toutes les versions du produit ne sont pas identifiées dans cet article.
Impact
Medium
Détails
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-22455 | Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-22455 | Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Produits concernés et mesure corrective
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2024-22455 | Mobility - E-Lab Navigator | Versions 3.1.9 and 3.2.0 | Version 3.3.3 | https://play.google.com/store/apps/details?id=com.emc.mobileapps.elabnavigator&pcampaignid=web_share |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2024-22455 | Mobility - E-Lab Navigator | Versions 3.1.9 and 3.2.0 | Version 3.3.3 | https://play.google.com/store/apps/details?id=com.emc.mobileapps.elabnavigator&pcampaignid=web_share |
Solutions de contournement et mesures d’atténuation
None
Historique des révisions
| Revision | Date | Description |
| 1.0 | 2024-02-12 | Initial Release |
| 2.0 | 2024-10-30 | Updated CVE Description |
Remerciements
Dell Technologies would like to thank iow1n3r for reporting this issue.
Informations connexes
Mention légale
Produits concernés
E-Lab Navigator - MobilePropriétés de l’article
Numéro d’article: 000222015
Type d’article: Dell Security Advisory
Dernière modification: 30 Oct 2024
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.