CVE-2022-34404: Medium severity dell update vulnerability
Published Feb 10, 2023
·Updated
Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service.
Affected Software
1 affected component
Dell System Update<2.0.1.0
Event History
Feb 10, 2023
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-34404?
CVE-2022-34404 is classified as a high severity vulnerability due to its potential for credential theft and denial of service.
2
How do I fix CVE-2022-34404?
To fix CVE-2022-34404, upgrade to Dell System Update version 2.0.1.0 or later.
3
Who can exploit CVE-2022-34404?
CVE-2022-34404 can be exploited by a local attacker with high privileges on the affected system.
4
What impact does CVE-2022-34404 have?
The impact of CVE-2022-34404 includes potential credential theft and denial of service.
5
Which versions of Dell System Update are affected by CVE-2022-34404?
Dell System Update versions 2.0.0 and earlier are affected by CVE-2022-34404.