CVE-2024-47480

Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege attacker with local access may exploit this vulnerability, potentially resulting in Elevation of Privileges and unauthorized file system access.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:inventory_collector:*:*:*:*:*:*:*:*

History

04 Feb 2025, 15:56

Type Values Removed Values Added
CPE cpe:2.3:a:dell:inventory_collector:*:*:*:*:*:*:*:*
First Time Dell inventory Collector
Dell
CWE CWE-59
References () https://www.dell.com/support/kbdoc/en-us/000255700/dsa-2024-475 - () https://www.dell.com/support/kbdoc/en-us/000255700/dsa-2024-475 - Vendor Advisory

18 Dec 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-18 03:15

Updated : 2025-02-04 15:56


NVD link : CVE-2024-47480

Mitre link : CVE-2024-47480

CVE.ORG link : CVE-2024-47480


JSON object : View

Products Affected

dell

  • inventory_collector
CWE
CWE-61

UNIX Symbolic Link (Symlink) Following

CWE-59

Improper Link Resolution Before File Access ('Link Following')