DSA-2023-074: Dell Trusted Device Agent Security Update for an Improper Installation Permissions Vulnerability
Riepilogo: Dell Trusted Device Agent remediation is available for an improper installation permissions vulnerability that could be exploited by malicious users to compromise the affected system.
Questo articolo si applica a
Questo articolo non si applica a
Questo articolo non è legato a un prodotto specifico.
Non tutte le versioni del prodotto sono identificate in questo articolo.
Impatto
High
Dettagli
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges. | 7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges. | 7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Prodotti interessati e correzione
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent | Versions prior to 5.3.0 |
5.3.0 | https://www.dell.com/support/home/product-support/product/trusted-device/drivers |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent | Versions prior to 5.3.0 |
5.3.0 | https://www.dell.com/support/home/product-support/product/trusted-device/drivers |
Soluzioni alternative e mitigazioni
Uninstall and re-install Dell Trusted Device Agent with default settings.
Cronologia delle revisioni
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-04-04 | Initial Release |
Ringraziamenti
CVE-2023-25542: Dell Technologies would like to thank Marius Gabriel Mihai for reporting this issue.
Informazioni correlate
Dichiarazione di non responsabilità
Prodotti interessati
Product Security Information, Dell Trusted DeviceProprietà dell'articolo
Numero articolo: 000209461
Tipo di articolo: Dell Security Advisory
Ultima modifica: 04 apr 2023
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.