
Cloud Vulnerability DB
A community-led vulnerabilities database
Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. The vulnerability, tracked as CVE-2023-28047, was disclosed on April 20, 2023. This security flaw affects Dell Display Manager software installations and could allow local attackers with low privileges to potentially execute arbitrary code with elevated system privileges (NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The attack vector is local (AV:L), requiring low attack complexity (AC:L) and low privileges (PR:L). No user interaction (UI:N) is needed for exploitation. The scope is unchanged (S:U), with high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H) (NVD, Dell Advisory).
If successfully exploited, this vulnerability could lead to the execution of arbitrary code on the operating system with high privileges. The high CVSS score indicates severe potential impacts on system confidentiality, integrity, and availability, potentially allowing attackers to gain significant control over the affected system (Dell Advisory).
The vulnerability requires local access to the system and low privileges for exploitation. While the attack complexity is rated as low, the attacker must have local access to the affected system during the installation process of Dell Display Manager (NVD).
Dell has released version 2.1.1 of Dell Display Manager to address this vulnerability. Users are strongly advised to update to this version or later to mitigate the security risk. No alternative workarounds have been provided by Dell (Dell Advisory).
Dell acknowledged Marius Gabriel Mihai for reporting this security issue. The vulnerability was assigned a high severity rating, indicating its significant potential impact on affected systems (Dell Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."