CVE-2024-37129

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
dellCNA
6.7 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
VendorProductVersion
dellcommand_update
𝑥
< 12.3.0.6
dellupdate
𝑥
< 12.3.0.6
dellalienware_update
𝑥
< 12.3.0.6
dellsupportassist_for_home_pcs
𝑥
< 12.3.0.6
dellsupportassist_for_business_pcs
𝑥
< 12.3.0.6
dellinventory_collector
𝑥
< 12.3.0.6
𝑥
= Vulnerable software versions