Impact
Dell Command | Monitor (DCM) versions prior to 10.13.2 contain an Incorrect Permission Assignment for Critical Resource vulnerability that allows a local user with low privileges to gain elevated privileges by manipulating a protected resource. This flaw can be used to bypass the intended access controls on the system, giving the attacker full control over the affected device.
Affected Systems
The vulnerability is present in Dell Command | Monitor (DCM) software prior to version 10.13.2, specifically in the Dell:Command | Monitor product line.
Risk and Exploitability
The CVSS score of 8.4 signals a high‑severity issue, but the EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating that widespread exploitation has not yet been observed. Because the attack requires local access, the risk is confined to environments where attackers can physically or otherwise gain local user rights. Nonetheless, the potential for privilege escalation makes timely patching critical.
OpenCVE Enrichment