HIGH✓ PATCH🇬🇧 English

CVE-2023-23696

CVSS 7.0v3.1pub. 2023-02-07upd. 2024-11-21

Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious users could potentially exploit this vulnerability in order to write arbitrary files to the system.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Dell Command \| Intel Vpro Out Of Band

    APP
    Dell
    < 4.4.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2026-24502HIGH8.8ten sam produkt

Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vu...

CVE-2023-23697MEDIUM4.7ten sam produkt

Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability...

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓ten sam vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)

CVE-2026-54489CRITICAL9.1PL ✓ten sam vendor

Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta

CVE-2026-67261CRITICAL9.8PL ✓ten sam vendor

Dell Virtual Storage Integrator – OS Command Injection z uprawnieniami root (RCE bez uwierzytelnienia)