Description
Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
Published: 2026-09-21
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

Dell Command | Integration Suite for System Center contains an Incorrect Default Permissions vulnerability that allows a local adversary with limited privileges to read sensitive data. The flaw arises from improperly configured default permissions on files or directories, facilitating information disclosure. The impact is limited to confidentiality; the attacker cannot modify data or execute code, but can expose sensitive configuration or credentials.

Affected Systems

The vulnerability affects Dell Command | Integration Suite for System Center versions earlier than 6.7.2. Any deployment of these versions on Windows systems remains susceptible, regardless of network exposure, as the exploit requires local access.

Risk and Exploitability

The CVSS score is 5.5, reflecting a moderate risk. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local with low-privileged credentials; the adversary must be able to log into the system, but does not need exploitation of code execution or remote access. Because permissions are the root cause, a simple file read action can satisfy the attack chain.

Generated by OpenCVE AI on September 21, 2026 at 19:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell Command | Integration Suite for System Center version 6.7.2 or later, which corrects the default permissions.
  • Review the permissions on sensitive directories and configuration files to ensure they no longer grant unwarranted access to local users.
  • Use the principle of least privilege for local accounts; disable or delete any accounts that are not required for normal operation, and enforce strong authentication.

Generated by OpenCVE AI on September 21, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Incorrect Default Permissions Leading to Information Disclosure in Dell Command | Integration Suite for System Center
First Time appeared Dell
Dell command | Integration Suite For System Center
Vendors & Products Dell
Dell command | Integration Suite For System Center

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Command | Integration Suite For System Center
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-21T18:48:14.541Z

Reserved: 2026-08-28T07:04:31.455Z

Link: CVE-2026-82165

cve-icon Vulnrichment

Updated: 2026-09-21T18:48:08.089Z

cve-icon NVD

Status : Received

Published: 2026-09-21T19:17:12.617

Modified: 2026-09-21T19:17:12.617

Link: CVE-2026-82165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:30:15Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions