Impact
The vulnerability in Dell Command Update is a Missing Authorization flaw that permits a low‑privileged local user to gain unauthorized access to administrative functionalities. Classified as CWE‑862, the issue could let an attacker execute privileged actions or alter system settings without proper authentication.
Affected Systems
Affecting Dell Command Update (DCU) versions prior to 5.7.1; users running any DCU release older than 5.7.1 are potentially exposed.
Risk and Exploitability
The CVSS score of 7.3 indicates moderate to high risk. Exploitation requires local access by a low‑privileged user, making it relatively feasible for internal threat actors. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, yet the missing authorization still permits local privilege escalation and unauthorized configuration changes.
OpenCVE Enrichment