CVE-2024-25957

Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in its appsync module. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure that could be used to access the appsync application with elevated privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:grab:*:*:*:*:*:windows:*:*

History

28 Jan 2025, 18:54

Type Values Removed Values Added
First Time Dell grab
Dell
References () https://www.dell.com/support/kbdoc/en-us/000223508/dsa-2024-121-security-update-for-grab-for-windows-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000223508/dsa-2024-121-security-update-for-grab-for-windows-vulnerabilities - Vendor Advisory
CPE cpe:2.3:a:dell:grab:*:*:*:*:*:windows:*:*

21 Nov 2024, 09:01

Type Values Removed Values Added
Summary
  • (es) Dell Grab para Windows, versiones 5.0.4 y anteriores, contiene una vulnerabilidad de almacenamiento de texto plano de información confidencial en su módulo de sincronización de aplicaciones. Un atacante local autenticado podría explotar esta vulnerabilidad, lo que llevaría a la divulgación de información que podría usarse para acceder a la aplicación appsync con privilegios elevados.
References () https://www.dell.com/support/kbdoc/en-us/000223508/dsa-2024-121-security-update-for-grab-for-windows-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000223508/dsa-2024-121-security-update-for-grab-for-windows-vulnerabilities -

26 Mar 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-26 16:15

Updated : 2025-01-28 18:54


NVD link : CVE-2024-25957

Mitre link : CVE-2024-25957

CVE.ORG link : CVE-2024-25957


JSON object : View

Products Affected

dell

  • grab
CWE
CWE-532

Insertion of Sensitive Information into Log File