Impact
Dell Command | Configure (DCC) contains a Use of Hard‑coded Cryptographic Key vulnerability that allows an attacker to potentially read protected configuration data, exposing sensitive information. The vulnerability arises when the software relies on a fixed cryptographic key for encryption and decryption tasks, enabling privileged local users to bypass confidentiality safeguards. The impact is the disclosure of confidential data rather than remote code execution or denial of service.
Affected Systems
Products affected are Dell Command | Configure versions prior to 5.2.3.35. The vulnerability is limited to the DCC suites deployed by Dell, and any systems still running those earlier versions may be exposed.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, and with an unauthenticated local attack vector the risk is significant for organizations that provide local access to users who should not have the ability to read configuration files. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Nonetheless, the presence of a hard‑coded key means that once local access is achieved, an attacker could read sensitive data instantly without complex exploitation.
OpenCVE Enrichment