Description
Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-08-19
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Command Update versions prior to 5.7.1 contain a vulnerability that exposes sensitive system information to an unauthorized control sphere. A low‑privileged attacker with local access could leverage this flaw, causing disclosure of confidential data without elevating privileges.

Affected Systems

The affected product is Dell Command Update (DCU) for Dell systems, with all releases before version 5.7.1 susceptible to exploitation.

Risk and Exploitability

The severity is quantified with a CVSS score of 5.5, indicating moderate risk. The EPSS score indicates a very low but nonzero exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation. The attack vector is local and requires low privilege, meaning it is only exploitable by users who can run applications on the affected system, such as local administrators or users with sufficient access rights.

Generated by OpenCVE AI on August 20, 2026 at 15:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell Command Update 5.7.1 or later as released in the Dell security advisory.
  • If patch deployment is delayed, isolate the affected systems from external networks and restrict local user privileges to prevent unauthorized local access.
  • Verify that local accounts do not have unnecessary administrative rights and implement least‑privilege policies.

Generated by OpenCVE AI on August 20, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell command Update
CPEs cpe:2.3:a:dell:command_update:*:*:*:*:*:*:*:*
Vendors & Products Dell command Update

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Command Update (dcu)
Vendors & Products Dell
Dell dell Command Update (dcu)

Thu, 20 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Exposure of Sensitive System Information to Unauthorized Control Sphere in Dell Command Update

Wed, 19 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Exposure of Sensitive System Information to Unauthorized Control Sphere in Dell Command Update

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Command Update Dell Command Update (dcu)
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T15:19:07.802Z

Reserved: 2026-07-29T11:04:32.678Z

Link: CVE-2026-67267

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T15:17:51.767

Modified: 2026-08-21T13:41:18.347

Link: CVE-2026-67267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T15:30:03Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere