CVE-2023-43086: High severity Dell Command\|configure vulnerability
Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local malicious user could potentially modify files inside installation folder during application upgrade, leading to privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Command | Configureto a version that resolves this vulnerability.Fixed in 4.11.0
Event History
Frequently Asked Questions
What is CVE-2023-43086?
CVE-2023-43086 is an improper access control vulnerability in Dell Command | Configure versions prior to 4.11.0.
How severe is CVE-2023-43086?
CVE-2023-43086 has a severity rating of 7.3, which is considered high.
What is the impact of CVE-2023-43086?
CVE-2023-43086 can lead to privilege escalation if a local malicious user modifies files inside the installation folder during application upgrade.
How can I fix CVE-2023-43086?
To fix CVE-2023-43086, it is recommended to update Dell Command | Configure to version 4.11.0 or later.
Where can I find more information about CVE-2023-43086?
More information about CVE-2023-43086 can be found at the following reference: [https://www.dell.com/support/kbdoc/en-us/000218424/dsa-2023-387-security-update-for-a-dell-command-configure-vulnerability](https://www.dell.com/support/kbdoc/en-us/000218424/dsa-2023-387-security-update-for-a-dell-command-configure-vulnerability)