Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xwp-3v4p-x875

Опубликовано: 18 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.

Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.

EPSS

Процентиль: 14%
0.00046
Низкий

7.8 High

CVSS3

Дефекты

CWE-284
CWE-668
CWE-732

Связанные уязвимости

CVSS3: 7.3
nvd
около 3 лет назад

Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.

CVSS3: 7.3
fstec
больше 3 лет назад

Уязвимость пакета приложений для настройки BIOS Dell Command Configure, связанная с неправильной обработкой разрешений, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 14%
0.00046
Низкий

7.8 High

CVSS3

Дефекты

CWE-284
CWE-668
CWE-732