Vulnerability Details CVE-2023-39254
Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.7%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2023-39254
-
cpe:2.3:a:dell:update_package_framework:-
-
cpe:2.3:a:dell:update_package_framework:3.8.3.67
-
cpe:2.3:a:dell:update_package_framework:4.9.4.36