Vulnerability Details CVE-2019-18575
Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticated malicious user could exploit this vulnerability by creating a symlink to a target file, allowing the attacker to overwrite or corrupt a specified file on the system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.6%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 6.6
Products affected by CVE-2019-18575
-
cpe:2.3:a:dell:command|configure:3.0
-
cpe:2.3:a:dell:command|configure:3.1
-
cpe:2.3:a:dell:command|configure:3.1.2
-
cpe:2.3:a:dell:command|configure:3.2
-
cpe:2.3:a:dell:command|configure:3.3
-
cpe:2.3:a:dell:command|configure:4.0
-
cpe:2.3:a:dell:command|configure:4.1