Dell command configuration, version 4.8 and prior,...
High severity
Unreviewed
Published
Jan 18, 2023
to the GitHub Advisory Database
•
Updated Jul 30, 2023
Description
Published by the National Vulnerability Database
Jan 18, 2023
Published to the GitHub Advisory Database
Jan 18, 2023
Last updated
Jul 30, 2023
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.
References