« Volver al listado

CVE-2023-23698

Estado: ModificadaAlta (7.1)—

Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-23698",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-23698",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-24T14:55:40.789063Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "Dell Command Update (DCU)",
          "versions": [
            {
              "status": "affected",
              "version": "Versions 4.6.0 and 4.7.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-02-10T13:15:11.337",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000208038/dsa-2023-031",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000208038/dsa-2023-031",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1386"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nDell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete.\n\n"
    },
    {
      "lang": "es",
      "value": "Dell Command | Update, Dell Update, and Alienware Update anteriores a 4.6.0 y 4.7.1 contienen operación insegura en Windows Junction en el componente del instalador. Un usuario malintencionado local podría explotar esta vulnerabilidad y provocar la eliminación arbitraria de archivos."
    }
  ],
  "lastModified": "2026-06-17T05:37:45.083",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:alienware_update:4.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10E69226-6D72-4E15-89C3-B95E00BF91A0"
            },
            {
              "criteria": "cpe:2.3:a:dell:alienware_update:4.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4651608F-B893-4D9F-B3CB-AD3B9DC1EEE3"
            },
            {
              "criteria": "cpe:2.3:a:dell:command_update:4.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9836FDEF-5971-45AE-AD0F-AEFB657F6AAB"
            },
            {
              "criteria": "cpe:2.3:a:dell:command_update:4.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "350DEA8B-0DE7-4025-9124-ABA67D5CC8FC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}