Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34458


Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability leading to the disclosure of confidential data.


Published

2023-02-01T05:15:12.417

Last Modified

2024-11-21T07:09:36.670

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.6 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-497
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell alienware_update < 4.7.1 Yes
Application dell command_update < 4.7.1 Yes
Application dell update < 4.7.1 Yes

References