Impact
Dell Command Update versions prior to 5.7.1 contain a vulnerability that exposes sensitive system information to an unauthorized control sphere. A low‑privileged attacker with local access could leverage this flaw, causing disclosure of confidential data without elevating privileges.
Affected Systems
The affected product is Dell Command Update (DCU) for Dell systems, with all releases before version 5.7.1 susceptible to exploitation.
Risk and Exploitability
The severity is quantified with a CVSS score of 5.5, indicating moderate risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation. The attack vector is local and requires low privilege, meaning it is only exploitable by users who can run applications on the affected system, such as local administrators or users with sufficient access rights.
OpenCVE Enrichment