CVE-2024-22455

Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:e-lab_navigator:3.1.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:e-lab_navigator:3.2.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.6
v2 : unknown
v3 : 4.4
References () https://www.dell.com/support/kbdoc/en-us/000222015/dsa-2024-073-security-update-for-mobility-e-lab-navigator-vulnerabilities - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000222015/dsa-2024-073-security-update-for-mobility-e-lab-navigator-vulnerabilities - Vendor Advisory

30 Oct 2024, 15:15

Type Values Removed Values Added
CWE CWE-451
Summary (en) Dell E-Lab Navigator, [3.1.9, 3.2.0], contains an Insecure Direct Object Reference Vulnerability in Feedback submission. An attacker could potentially exploit this vulnerability, to manipulate the email's appearance, potentially deceiving recipients and causing reputational and security risks. (en) Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks.

16 Oct 2024, 16:10

Type Values Removed Values Added
First Time Dell
Dell e-lab Navigator
References () https://www.dell.com/support/kbdoc/en-us/000222015/dsa-2024-073-security-update-for-mobility-e-lab-navigator-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000222015/dsa-2024-073-security-update-for-mobility-e-lab-navigator-vulnerabilities - Vendor Advisory
CVSS v2 : unknown
v3 : 4.4
v2 : unknown
v3 : 4.6
CPE cpe:2.3:a:dell:e-lab_navigator:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:e-lab_navigator:3.1.9:*:*:*:*:*:*:*
CWE CWE-639
Summary
  • (es) Dell E-Lab Navigator, [3.1.9, 3.2.0], contiene una vulnerabilidad de referencia directa a objetos inseguros en el envío de comentarios. Un atacante podría explotar esta vulnerabilidad para manipular la apariencia del correo electrónico, engañando potencialmente a los destinatarios y provocando riesgos para la reputación y la seguridad.

14 Feb 2024, 13:59

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 07:15

Updated : 2024-11-21 08:56


NVD link : CVE-2024-22455

Mitre link : CVE-2024-22455

CVE.ORG link : CVE-2024-22455


JSON object : View

Products Affected

dell

  • e-lab_navigator
CWE
CWE-639

Authorization Bypass Through User-Controlled Key