Description
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Watchdog Timer Driver versions before 2.0.0.1 contain an exposed IOCTL that fails to enforce proper access control. An attacker who already has local, low‑privileged access could invoke the ioctl and obtain elevated privileges. The weakness is classified as CWE‑698, which focuses on improper access control.

Affected Systems

This vulnerability affects Dell’s Watchdog Timer Driver. All installations running any version earlier than 2.0.0.1 are impacted.

Risk and Exploitability

The CVSS score of 8.8 classifies the issue as high severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, but the local attack nature and role elevation of the flaw raise concern. An attacker only needs local access and the ability to trigger the exposed ioctl to reach the elevated state.

Generated by OpenCVE AI on August 18, 2026 at 17:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s security update that introduces Watchdog Timer Driver 2.0.0.1 or newer. This patch removes the exposed ioctl and restores proper access control.
  • If the patch cannot be applied immediately, limit local access to the driver by adjusting kernel module permissions or disabling the watchdog timer service.
  • Monitor system logs for repeated attempts to invoke the specific ioctl to detect exploitation activity.

Generated by OpenCVE AI on August 18, 2026 at 17:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell watchdog Timer Driver
Vendors & Products Dell
Dell watchdog Timer Driver

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Exposed IOCTL in Dell Watchdog Timer Driver Enables Local Privilege Escalation

Tue, 18 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Weaknesses CWE-698
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Watchdog Timer Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-20T03:55:57.028Z

Reserved: 2026-07-09T11:05:01.705Z

Link: CVE-2026-61407

cve-icon Vulnrichment

Updated: 2026-08-18T18:03:14.612Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T15:16:56.310

Modified: 2026-08-20T13:02:12.153

Link: CVE-2026-61407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:33:08Z

Weaknesses
  • CWE-698

    Execution After Redirect (EAR)