CVE Vulnerabilities

CVE-2024-28962

Externally Controlled Reference to a Resource in Another Sphere

Published: Aug 06, 2024 | Modified: Aug 19, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

Weakness

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Alienware_update Dell * 5.4 (excluding)
Command_update Dell * 5.4 (excluding)
Update Dell * 5.4 (excluding)

References