CVE-2024-22455

Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:e-lab_navigator:3.1.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:e-lab_navigator:3.2.0:*:*:*:*:*:*:*

History

30 Oct 2024, 15:15

Type Values Removed Values Added
Summary (en) Dell E-Lab Navigator, [3.1.9, 3.2.0], contains an Insecure Direct Object Reference Vulnerability in Feedback submission. An attacker could potentially exploit this vulnerability, to manipulate the email's appearance, potentially deceiving recipients and causing reputational and security risks. (en) Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks.
CWE CWE-451

16 Oct 2024, 16:10

Type Values Removed Values Added
First Time Dell e-lab Navigator
Dell
References () https://www.dell.com/support/kbdoc/en-us/000222015/dsa-2024-073-security-update-for-mobility-e-lab-navigator-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000222015/dsa-2024-073-security-update-for-mobility-e-lab-navigator-vulnerabilities - Vendor Advisory
Summary
  • (es) Dell E-Lab Navigator, [3.1.9, 3.2.0], contiene una vulnerabilidad de referencia directa a objetos inseguros en el envío de comentarios. Un atacante podría explotar esta vulnerabilidad para manipular la apariencia del correo electrónico, engañando potencialmente a los destinatarios y provocando riesgos para la reputación y la seguridad.
CWE CWE-639
CPE cpe:2.3:a:dell:e-lab_navigator:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:e-lab_navigator:3.1.9:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 4.4
v2 : unknown
v3 : 4.6

14 Feb 2024, 13:59

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 07:15

Updated : 2024-10-30 15:15


NVD link : CVE-2024-22455

Mitre link : CVE-2024-22455

CVE.ORG link : CVE-2024-22455


JSON object : View

Products Affected

dell

  • e-lab_navigator
CWE
CWE-639

Authorization Bypass Through User-Controlled Key