Show plain JSON{"id": "CVE-2022-34457", "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "security_alert@emc.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.3, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.3}, {"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.8}]}, "published": "2023-01-18T12:15:10.587", "references": [{"url": "https://www.dell.com/support/kbdoc/000205633", "tags": ["Patch", "Vendor Advisory"], "source": "security_alert@emc.com"}, {"url": "https://www.dell.com/support/kbdoc/000205633", "tags": ["Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "security_alert@emc.com", "description": [{"lang": "en", "value": "CWE-284"}]}, {"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-732"}]}], "descriptions": [{"lang": "en", "value": "\nDell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.\n\n\n\n\n\n"}, {"lang": "es", "value": "Las versiones 4.8 y anteriores de la aplicaci\u00f3n Dell Command | Configure contienen permisos de carpeta inadecuados cuando se instala en una ruta no segura en lugar de la predeterminada. Esta es una vulnerabilidad cr\u00edtica ya que puede derivar en una escalada de privilegios, permitiendo que usuarios que no son administradores modifiquen los archivos dentro del directorio instalado y pueden hacer que la aplicaci\u00f3n no est\u00e9 disponible para todos los usuarios."}], "lastModified": "2024-11-21T07:09:36.520", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:dell:command\\|configure:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "61AC5838-DDD5-4F68-8D37-29F9D2783B32", "versionEndExcluding": "4.9.0"}], "operator": "OR"}]}], "sourceIdentifier": "security_alert@emc.com"}