Impact
Dell Command | Integration Suite for System Center contains an Incorrect Default Permissions vulnerability that allows a local adversary with limited privileges to read sensitive data. The flaw arises from improperly configured default permissions on files or directories, facilitating information disclosure. The impact is limited to confidentiality; the attacker cannot modify data or execute code, but can expose sensitive configuration or credentials.
Affected Systems
The vulnerability affects Dell Command | Integration Suite for System Center versions earlier than 6.7.2. Any deployment of these versions on Windows systems remains susceptible, regardless of network exposure, as the exploit requires local access.
Risk and Exploitability
The CVSS score is 5.5, reflecting a moderate risk. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local with low-privileged credentials; the adversary must be able to log into the system, but does not need exploitation of code execution or remote access. Because permissions are the root cause, a simple file read action can satisfy the attack chain.
OpenCVE Enrichment