High
Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
---|---|---|---|
CVE-2023-22576 | Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary executable on the operating system with high privileges using the existing vulnerability in operating system. Exploitation may lead to unavailability of the service. |
7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
---|---|---|---|
CVE-2023-22576 | Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary executable on the operating system with high privileges using the existing vulnerability in operating system. Exploitation may lead to unavailability of the service. |
7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVEs Addressed |
Product | Affected Versions | Remediated Versions | Link |
---|---|---|---|---|
CVE-2023-22576 | Dell Repository Manager (DRM) | 3.4.2 and earlier | 3.4.3 | Link to Download |
CVEs Addressed |
Product | Affected Versions | Remediated Versions | Link |
---|---|---|---|---|
CVE-2023-22576 | Dell Repository Manager (DRM) | 3.4.2 and earlier | 3.4.3 | Link to Download |
CVE ID | Workaround and Mitigation |
---|---|
CVE-2023-22576 | Installing DRM in default path, such as C:\Program Files, does not enable this vulnerability. |
Revision | Date | Description |
1.0 | 2023-01-13 | Initial Release |
2.0 | 2023-01-27 | Update |
3.0 | 2023-07-10 | Updated for enhanced presentation with no changes to content |
Dell would like to thank Marius Gabriel Mihai for reporting this issue.