CVE-2024-22455

Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:e-lab_navigator:3.1.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:e-lab_navigator:3.2.0:*:*:*:*:*:*:*

History

30 Oct 2024, 15:15

Type Values Removed Values Added
CWE CWE-451
Summary (en) Dell E-Lab Navigator, [3.1.9, 3.2.0], contains an Insecure Direct Object Reference Vulnerability in Feedback submission. An attacker could potentially exploit this vulnerability, to manipulate the email's appearance, potentially deceiving recipients and causing reputational and security risks. (en) Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks.

16 Oct 2024, 16:10

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000222015/dsa-2024-073-security-update-for-mobility-e-lab-navigator-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000222015/dsa-2024-073-security-update-for-mobility-e-lab-navigator-vulnerabilities - Vendor Advisory
CVSS v2 : unknown
v3 : 4.4
v2 : unknown
v3 : 4.6
CWE CWE-639
CPE cpe:2.3:a:dell:e-lab_navigator:3.1.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:e-lab_navigator:3.2.0:*:*:*:*:*:*:*
First Time Dell
Dell e-lab Navigator

14 Feb 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 07:15

Updated : 2024-10-30 15:15


NVD link : CVE-2024-22455

Mitre link : CVE-2024-22455

CVE.ORG link : CVE-2024-22455


JSON object : View

Products Affected

dell

  • e-lab_navigator
CWE
CWE-639

Authorization Bypass Through User-Controlled Key