Impact
Dell Command Update (DCU) versions before 5.7.1 contain an Incorrect Authorization flaw that allows a local user with low privileges to bypass access controls and gain higher level permissions on the affected system. The vulnerability enables local attackers to execute privileged actions, potentially compromising system integrity and control.
Affected Systems
The affected product is Dell Command Update (DCU) from Dell. All installations with a version less than 5.7.1 are vulnerable. Version 5.7.1 and later contain the fix.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and a low‑privileged account; once accessed, an attacker can elevate privileges to administrator or elevated user and potentially perform further malicious actions. The overall risk is moderate, with exploitation limited to environments where local user accounts are not tightly controlled.
OpenCVE Enrichment