CVE-2023-23696

Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious users could potentially exploit this vulnerability in order to write arbitrary files to the system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:command_\|_intel_vpro_out_of_band:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:46

Type Values Removed Values Added
Summary
  • (es) Dell Command Intel vPro Out of Band, versiones anteriores a la 4.3.1, contienen una vulnerabilidad de autorización incorrecta. Un usuario malintencionado autenticado localmente podría explotar esta vulnerabilidad para escribir archivos arbitrarios en el sistema.
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 7.0
References () https://www.dell.com/support/kbdoc/en-us/000208331/dsa-2023-029-dell-command-intel-vpro-out-of-band-security-update-for-an-improper-authorization-vulnerability - Patch, Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000208331/dsa-2023-029-dell-command-intel-vpro-out-of-band-security-update-for-an-improper-authorization-vulnerability - Patch, Vendor Advisory

07 Nov 2023, 04:07

Type Values Removed Values Added
Summary Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious users could potentially exploit this vulnerability in order to write arbitrary files to the system. Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious users could potentially exploit this vulnerability in order to write arbitrary files to the system.

Information

Published : 2023-02-07 10:15

Updated : 2024-11-21 07:46


NVD link : CVE-2023-23696

Mitre link : CVE-2023-23696

CVE.ORG link : CVE-2023-23696


JSON object : View

Products Affected

dell

  • command_\|_intel_vpro_out_of_band
CWE
CWE-285

Improper Authorization

CWE-863

Incorrect Authorization