CVE-2024-37129

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:inventory_collector:*:*:*:*:*:*:*:*

History

13 Aug 2024, 15:26

Type Values Removed Values Added
CPE cpe:2.3:a:dell:inventory_collector:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000225779/dsa-2024-263 - () https://www.dell.com/support/kbdoc/en-us/000225779/dsa-2024-263 - Vendor Advisory
First Time Dell inventory Collector
Dell
CVSS v2 : unknown
v3 : 6.7
v2 : unknown
v3 : 7.8

31 Jul 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Dell Inventory Collector, versiones anteriores a 12.3.0.6, contiene una vulnerabilidad de Path Traversal. Un usuario malintencionado autenticado local podría aprovechar esta vulnerabilidad, lo que provocaría la ejecución de código arbitrario en el sistema.

31 Jul 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-31 09:15

Updated : 2024-08-13 15:26


NVD link : CVE-2024-37129

Mitre link : CVE-2024-37129

CVE.ORG link : CVE-2024-37129


JSON object : View

Products Affected

dell

  • inventory_collector
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')