Impact
The vulnerability is an Improper Link Resolution Before File Access flaw that lets a low‑privileged local user overwrite any file the application can access. The flaw can be used to modify configuration files, place malicious executables, or otherwise corrupt system state, compromising integrity and potentially availability of the affected service. The weakness is identified as CWE‑1386.
Affected Systems
Dell Inventory Collector Client versions older than 13.8.0 are affected. Dell is the vendor, and the CVE references Dell’s support documentation for these builds.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting it is not widely exploited yet. The attack requires local access and low privileges; an attacker with local user rights could simply execute the client and trigger the link follow to write arbitrary files. The risk is therefore moderate for systems that grant local users access to the Inventory Collector Client.
OpenCVE Enrichment