DSA-2024-073: Security Update for Dell Mobility - E-Lab Navigator Vulnerabilities
요약: Dell Mobility - E-Lab Navigator remediation is available for insecure direct object vulnerability that could be exploited by malicious users to compromise the affected system.
이 문서는 다음에 적용됩니다.
이 문서는 다음에 적용되지 않습니다.
이 문서는 특정 제품과 관련이 없습니다.
모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.
영향
Medium
세부 정보
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-22455 | Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-22455 | Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
영향을 받는 제품 및 문제 해결
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2024-22455 | Mobility - E-Lab Navigator | Versions 3.1.9 and 3.2.0 | Version 3.3.3 | https://play.google.com/store/apps/details?id=com.emc.mobileapps.elabnavigator&pcampaignid=web_share |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2024-22455 | Mobility - E-Lab Navigator | Versions 3.1.9 and 3.2.0 | Version 3.3.3 | https://play.google.com/store/apps/details?id=com.emc.mobileapps.elabnavigator&pcampaignid=web_share |
해결 방법 및 완화 방안
None
개정 내역
| Revision | Date | Description |
| 1.0 | 2024-02-12 | Initial Release |
| 2.0 | 2024-10-30 | Updated CVE Description |
감사의 말
Dell Technologies would like to thank iow1n3r for reporting this issue.
관련 정보
법적 고지 사항
해당 제품
E-Lab Navigator - Mobile문서 속성
문서 번호: 000222015
문서 유형: Dell Security Advisory
마지막 수정 시간: 30 10월 2024
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.