Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3749

Опубликовано: 03 дек. 2019
Источник: nvd
CVSS3: 5.6
CVSS3: 5.5
CVSS2: 3.6
EPSS Низкий

Описание

Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any targeted file. This issue occurs because permissions on the Temp directory were set incorrectly.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dell:command_update:*:*:*:*:*:*:*:*
Версия до 3.1 (исключая)

EPSS

Процентиль: 15%
0.00049
Низкий

5.6 Medium

CVSS3

5.5 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-427
CWE-59

Связанные уязвимости

github
больше 3 лет назад

Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any targeted file. This issue occurs because permissions on the Temp directory were set incorrectly.

EPSS

Процентиль: 15%
0.00049
Низкий

5.6 Medium

CVSS3

5.5 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-427
CWE-59