Impact
Dell Command Powershell Provider (DCPP) versions earlier than 2.10.2 contain a flaw that causes sensitive data to be written to the event log. A low‑privileged attacker who can run code locally can trigger this behavior, resulting in the exposure of credentials or other confidential information. The vulnerability is an instance of CWE‑532, which involves the insertion of sensitive information into log files.
Affected Systems
The affected product is Dell Command Powershell Provider, versions prior to 2.10.2. No other vendors or products are listed in the CNA data.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity. Exploitation requires local low‑privilege access, so the attack surface is limited to machines where the attacker can run PowerShell commands. The EPSS score is not available, but the lack of a KEV listing suggests no publicly known exploit has been observed. Once bypassed, the attacker can read privileged data from the system event log, compromising confidentiality.
OpenCVE Enrichment