Description
Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
Published: 2026-09-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Tampering
Action: Immediate Patch
AI Analysis

Impact

Dell Trusted Device Client versions before 8.1.359.0 contain a critical permission assignment flaw that allows a low‑privileged local attacker to tamper with protected data, including modifying or deleting sensitive information stored by the client. This can compromise the integrity of the system’s data.

Affected Systems

Dell Trusted Device Client, versions prior to 8.1.359.0.

Risk and Exploitability

The CVSS score of 7.1 denotes a high severity risk. The vulnerability requires local access, so exploitation is confined to systems where an attacker has local user credentials. Because no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of exploitation depends on the presence of local accounts. Nevertheless, a local attacker that can execute the flaw could tamper with critical client data.

Generated by OpenCVE AI on September 25, 2026 at 06:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Trusted Device Client security update version 8.1.359.0 or later.
  • Restrict local accounts that can access the Trusted Device Client’s critical resources to users with appropriate privileges, disabling or removing the client for low‑privileged users.
  • Enable logging of permission changes to the Trusted Device Client and configure alerts for unauthorized modifications.

Generated by OpenCVE AI on September 25, 2026 at 06:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell trusted Device Client
Vendors & Products Dell
Dell trusted Device Client

Fri, 25 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Incorrect Permission Assignment in Dell Trusted Device Client

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Dell Trusted Device Client
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-24T19:30:31.588Z

Reserved: 2026-08-28T07:04:31.455Z

Link: CVE-2026-82164

cve-icon Vulnrichment

Updated: 2026-09-24T19:30:28.226Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-24T20:17:32.103

Modified: 2026-09-25T13:27:31.790

Link: CVE-2026-82164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T14:15:53Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource