CVE-2023-28047
Dell Display Manager vulnerability analysis and mitigation

Overview

Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. The vulnerability, tracked as CVE-2023-28047, was disclosed on April 20, 2023. This security flaw affects Dell Display Manager software installations and could allow local attackers with low privileges to potentially execute arbitrary code with elevated system privileges (NVD).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The attack vector is local (AV:L), requiring low attack complexity (AC:L) and low privileges (PR:L). No user interaction (UI:N) is needed for exploitation. The scope is unchanged (S:U), with high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H) (NVD, Dell Advisory).

Impact

If successfully exploited, this vulnerability could lead to the execution of arbitrary code on the operating system with high privileges. The high CVSS score indicates severe potential impacts on system confidentiality, integrity, and availability, potentially allowing attackers to gain significant control over the affected system (Dell Advisory).

Exploitability

The vulnerability requires local access to the system and low privileges for exploitation. While the attack complexity is rated as low, the attacker must have local access to the affected system during the installation process of Dell Display Manager (NVD).

Mitigation and workarounds

Dell has released version 2.1.1 of Dell Display Manager to address this vulnerability. Users are strongly advised to update to this version or later to mitigate the security risk. No alternative workarounds have been provided by Dell (Dell Advisory).

Community reactions

Dell acknowledged Marius Gabriel Mihai for reporting this security issue. The vulnerability was assigned a high severity rating, indicating its significant potential impact on affected systems (Dell Advisory).

Additional resources


SourceThis report was generated using AI

Related Dell Display Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-32451HIGH7.8
  • Dell Display Manager logoDell Display Manager
  • cpe:2.3:a:dell:display_manager
NoYesFeb 06, 2024
CVE-2023-28047HIGH7.8
  • Dell Display Manager logoDell Display Manager
  • cpe:2.3:a:dell:display_manager
NoYesApr 20, 2023
CVE-2025-22394HIGH7
  • Dell Display Manager logoDell Display Manager
  • cpe:2.3:a:dell:display_manager
NoYesJan 15, 2025
CVE-2023-32474MEDIUM6.6
  • Dell Display Manager logoDell Display Manager
  • cpe:2.3:a:dell:display_manager
NoYesFeb 06, 2024
CVE-2025-21101MEDIUM6.3
  • Dell Display Manager logoDell Display Manager
  • cpe:2.3:a:dell:display_manager
NoYesJan 15, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management