Lucene search

K
cve[email protected]CVE-2023-44296
HistoryNov 16, 2023 - 8:15 a.m.

CVE-2023-44296

2023-11-1608:15:31
CWE-798
web.nvd.nist.gov
26
cve-2023-44296
dell
elab-navigator
credential vulnerability
unauthorized access
sensitive data

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability. A local attacker could potentially exploit this vulnerability, leading to unauthorized access to sensitive data. Successful exploitation may result in the compromise of confidential user information.

Affected configurations

NVD
Node
delle-lab_navigatorMatch3.1.8
OR
delle-lab_navigatorMatch3.1.9

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Mobility - E-Lab Navigator",
    "vendor": "Dell",
    "versions": [
      {
        "status": "affected",
        "version": "Versions 3.1.8 and 3.1.9"
      }
    ]
  }
]

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2023-44296