Lucene search

K
cveDellCVE-2024-37130
HistoryJun 11, 2024 - 2:15 a.m.

CVE-2024-37130

2024-06-1102:15:08
CWE-427
dell
web.nvd.nist.gov
29
dell openmanage server
local privilege escalation
xsl hijacking
system compromise

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

9.0%

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this vulnerability and escalate their privilege to the admin user and gain full control of the machine. Exploitation may lead to a complete system compromise.

Affected configurations

Vulners
Vulnrichment
Node
dellopenmanage_server_administratorRange11.0.1.1
OR
dellopenmanage_server_administratorRange11.0.0.2
OR
dellopenmanage_server_administratorRange10.3.0.1
VendorProductVersionCPE
dellopenmanage_server_administrator*cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Dell OpenManage Server Administrator",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "11.0.1.1",
        "status": "affected",
        "version": "N/A",
        "versionType": "semver"
      },
      {
        "lessThan": "11.0.0.2",
        "status": "affected",
        "version": "N/A",
        "versionType": "semver"
      },
      {
        "lessThan": "10.3.0.1",
        "status": "affected",
        "version": "N/A",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2024-37130