CVE-2022-34457

Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.
References
Link Resource
https://www.dell.com/support/kbdoc/000205633 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:command\|configure:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:48

Type Values Removed Values Added
Summary Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users. Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.

21 Jul 2023, 18:48

Type Values Removed Values Added
CWE CWE-668 CWE-732

26 Jan 2023, 16:11

Type Values Removed Values Added
CPE cpe:2.3:a:dell:command\|configure:*:*:*:*:*:*:*:*
First Time Dell command\|configure
Dell
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References (MISC) https://www.dell.com/support/kbdoc/000205633 - (MISC) https://www.dell.com/support/kbdoc/000205633 - Patch, Vendor Advisory
CWE CWE-668

18 Jan 2023, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-18 12:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-34457

Mitre link : CVE-2022-34457

CVE.ORG link : CVE-2022-34457


JSON object : View

Products Affected

dell

  • command\|configure
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-284

Improper Access Control