Impact
Dell Update Package Framework versions released before 26.07.03 contain a stack-based buffer overflow that could allow an unauthenticated attacker with adjacent network access to execute arbitrary code remotely. This flaw, classified as CWE-121, may compromise confidentiality, integrity, and availability of the affected system by providing the attacker with a foothold to run malicious payloads. The CVE description indicates that exploitation would result in remote execution, revealing a severe impact on system security.
Affected Systems
All installations of Dell Update Package Framework running a pre‑26.07.03 version are impacted. The vulnerability applies to any system that hosts this framework, regardless of operating environment, as soon as it receives updates from an unauthenticated source on the same local network.
Risk and Exploitability
The CVSS score of 6.5 puts the vulnerability in the medium severity range, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The attack vector would be remote, requiring the attacker to be in the same local network segment that can contact the Update Package Framework service. Although the vulnerability is not listed in CISA’s KEV catalog, its potential for remote code execution makes immediate remediation advisable.
OpenCVE Enrichment