CVE-2023-39257
Last modified
CVE-2023-39257 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading to privilege escalation on the system. . EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading to privilege escalation on the system.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Rugged Control Center | < 4.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-39257?
How severe is CVE-2023-39257?
How do I fix CVE-2023-39257?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-39250 Dell Storage Integration Tools for VMware (DSITV) and Del…5.5
- CVE-2023-39251 Dell BIOS contains an Improper Input Validation vulnerabili…6.7
- CVE-2023-39252 Dell SCG Policy Manager 5.16.00.14 contains a broken crypt…5.9
- CVE-2023-39253 Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2…7.8
- CVE-2023-39254Dell Update Package (DUP), Versions prior to 4.9.10 contain …7.3
- CVE-2023-39256 Dell Rugged Control Center, version prior to 4.7, contains …7.8
- CVE-2023-39259 Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2…7.8
- CVE-2023-39261In JetBrains IntelliJ IDEA before 2023.2 plugin for Space wa…7.8
- CVE-2023-39264By default, stack traces for errors were enabled, which resu…4.3
- CVE-2023-39265Apache Superset would allow for SQLite database connections …6.5
- CVE-2023-39266A vulnerability in the ArubaOS-Switch web management interfa…6.1
- CVE-2023-39267An authenticated remote code execution vulnerability exists …6.5
Are you affected by CVE-2023-39257?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
