DSA-2021-232: Dell Wyse Device Agent Security Update for a Sensitive Data Disclosure Vulnerability

概要: Dell Wyse Device Agent contains remediation for a sensitive data disclosure vulnerability that may be exploited by malicious users to compromise the affected system.

この記事は次に適用されます: この記事は次には適用されません: この記事は、特定の製品に関連付けられていません。 すべての製品パージョンがこの記事に記載されているわけではありません。

影響

Medium

詳細

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2021-36341 Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated user with low privileges may potentially exploit this vulnerability and access sensitive information which can be used to perform unauthorized actions. 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2021-36341 Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated user with low privileges may potentially exploit this vulnerability and access sensitive information which can be used to perform unauthorized actions. 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
デル・テクノロジーズでは、すべてのお客様に対して、CVSSベース スコアに加えて、特定のセキュリティの脆弱性に付随する潜在的な重要度に影響する可能性のある現状スコアや環境スコアも考慮することをお勧めしています。

影響を受ける製品と修復

Product Affected Versions Updated Versions Link to Update
Dell Wyse Device Agent 14.5.4.1 and earlier  14.6.0.27 Dell Wyse Device Agent
Product Affected Versions Updated Versions Link to Update
Dell Wyse Device Agent 14.5.4.1 and earlier  14.6.0.27 Dell Wyse Device Agent

変更履歴

RevisionDateDescription
1.02021-12-6Initial Release

関連情報

対象製品

Product Security Information
文書のプロパティ
文書番号: 000193151
文書の種類: Dell Security Advisory
最終更新: 06 12月 2021
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。