CVE-2024-22455

Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:e-lab_navigator:3.1.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:e-lab_navigator:3.2.0:*:*:*:*:*:*:*

History

30 Oct 2024, 15:15

Type Values Removed Values Added
Summary Dell E-Lab Navigator, [3.1.9, 3.2.0], contains an Insecure Direct Object Reference Vulnerability in Feedback submission. An attacker could potentially exploit this vulnerability, to manipulate the email's appearance, potentially deceiving recipients and causing reputational and security risks. Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks.

16 Oct 2024, 16:10

Type Values Removed Values Added
CWE CWE-451 CWE-639
CPE cpe:2.3:a:dell:e-lab_navigator:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:e-lab_navigator:3.1.9:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
First Time Dell
Dell e-lab Navigator
References () https://www.dell.com/support/kbdoc/en-us/000222015/dsa-2024-073-security-update-for-mobility-e-lab-navigator-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000222015/dsa-2024-073-security-update-for-mobility-e-lab-navigator-vulnerabilities - Vendor Advisory

14 Feb 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 07:15

Updated : 2024-10-30 15:15


NVD link : CVE-2024-22455

Mitre link : CVE-2024-22455


JSON object : View

Products Affected

dell

  • e-lab_navigator
CWE
CWE-639

Authorization Bypass Through User-Controlled Key