7.8
CVE-2023-32479
- EPSS 0.04%
- Veröffentlicht 06.02.2024 08:15:51
- Zuletzt bearbeitet 21.11.2024 08:03:26
- Quelle security_alert@emc.com
- Teams Watchlist Login
- Unerledigt Login
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Encryption Version < 11.9.0
Dell ≫ Endpoint Security Suite Enterprise Version < 11.9.0
Dell ≫ Security Management Server Version < 11.9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.12 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
security_alert@emc.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.