Lucene search

K
cveDellCVE-2023-44281
HistoryJan 24, 2024 - 4:15 p.m.

CVE-2023-44281

2024-01-2416:15:08
CWE-264
dell
web.nvd.nist.gov
14
cve-2023-44281
dell
pair installer
eop
vulnerability
privilege
local access
dos

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

5.1%

Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially exploit this vulnerability to delete arbitrary files and result in Denial of Service.

Affected configurations

Nvd
Vulners
Node
dellpairRange<1.2.1
VendorProductVersionCPE
dellpair*cpe:2.3:a:dell:pair:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Dell Pair",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "1.2.1",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2023-44281