Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products

DSA-2023-017: Dell Repository Manager Security Update for an Improper Privilege Management Vulnerability

Summary: Dell Repository Manager remediation is available for an improper privilege management vulnerability that may be exploited by malicious users to compromise the affected system.

This article applies to   This article does not apply to 

Impact

High

Details

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2023-22576 Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary executable on the operating system with high privileges using the existing vulnerability in operating system. Exploitation may lead to unavailability of the service.
 
7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2023-22576 Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary executable on the operating system with high privileges using the existing vulnerability in operating system. Exploitation may lead to unavailability of the service.
 
7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

CVEs
Addressed  
Product Affected Versions Remediated Versions Link
CVE-2023-22576 Dell Repository Manager (DRM) 3.4.2 and earlier  3.4.3 Link to Download
CVEs
Addressed  
Product Affected Versions Remediated Versions Link
CVE-2023-22576 Dell Repository Manager (DRM) 3.4.2 and earlier  3.4.3 Link to Download

Workarounds & Mitigations

CVE ID Workaround and Mitigation
CVE-2023-22576 Installing DRM in default path, such as C:\Program Files, does not enable this vulnerability.

Revision History

RevisionDateDescription
1.02023-01-13Initial Release
2.02023-01-27Update
3.02023-07-10Updated for enhanced presentation with no changes to content  
 

 

 

Acknowledgements

Dell would like to thank Marius Gabriel Mihai for reporting this issue.

Related Information

Affected Products

Dell EMC Repository Manager 3.0, Dell EMC Repository Manager 3.0.1, Dell EMC Repository Manager 3.1, Dell EMC Repository Manager 3.2