CVE Vulnerabilities

CVE-2021-36277

Improper Verification of Cryptographic Signature

Published: Aug 09, 2021 | Modified: Feb 10, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability. A local authenticated malicious user may exploit this vulnerability by executing arbitrary code on the system.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Alienware_command_center_application Dell * 5.4.35.0 (excluding)
Command_ _update Dell *
Update/alienware_update Dell * 4.3.0 (excluding)

References