Lucene search

K
cveDellCVE-2024-25944
HistoryMar 29, 2024 - 5:15 p.m.

CVE-2024-25944

2024-03-2917:15:11
CWE-23
dell
web.nvd.nist.gov
36
cve-2024-25944
unauthenticated remote attacker
unauthorized access
server filesystem
web application
nvd

CVSS3

5.7

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.0%

Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesystem, with the privileges of the running web application.

Affected configurations

Vulners
Node
dellopenmanage_enterpriseRange4.0
VendorProductVersionCPE
dellopenmanage_enterprise*cpe:2.3:a:dell:openmanage_enterprise:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Dell OpenManage Enterprise\t",
    "vendor": "Dell",
    "versions": [
      {
        "lessThanOrEqual": "4.0",
        "status": "affected",
        "version": "N/A",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

5.7

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2024-25944