Dell Command Configure是美国戴尔(Dell)公司的一款能够为业务客户端平台提供配置功能的应用程序。该程序中包含用于配置多种BIOS功能的命令行界面和图形用户界面。 Dell Command Configure 4.8版本及之前版本存在安全漏洞,该漏洞源于文件夹权限不正确,导致权限升级。攻击者利用该漏洞修改目录中的文件,并使应用程序对所有用户都不可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dell | Dell Command Configure (DCC) | 0 ~ 4.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-32490 | 7.5 HIGH | Dell BIOS 输入验证错误漏洞 |
| CVE-2022-34401 | 7.5 HIGH | Dell BIOS 缓冲区错误漏洞 |
| CVE-2022-34460 | 7.5 HIGH | Dell BIOS 输入验证错误漏洞 |
| CVE-2022-34393 | 7.5 HIGH | Dell BIOS 输入验证错误漏洞 |
| CVE-2022-45103 | 6.5 MEDIUM | Dell EMC Unisphere for PowerMax 信息泄露漏洞 |
| CVE-2022-34399 | 5.1 MEDIUM | Dell Alienware 缓冲区错误漏洞 |
| CVE-2022-34436 | 2.7 LOW | Dell iDRAC8 输入验证错误漏洞 |
| CVE-2022-34435 | 2.7 LOW | Dell iDRAC9 输入验证错误漏洞 |
No comments yet