Impact
Dell System Update releases prior to version 2.3.0.0 contain a path traversal flaw that an unauthenticated attacker with remote access could exploit to gain filesystem read/write abilities. Successful exploitation can lead to arbitrary code execution and, as stated, potentially compromise the underlying operating system with root privileges, making it a critical vulnerability.
Affected Systems
The affected product is Dell System Update. All releases with a version number lower than 2.3.0.0 are vulnerable; newer builds are presumed patched.
Risk and Exploitability
The CVSS score of 9.6 ranks this flaw as critical, and although no EPSS score is published, the lack of public listing in CISA’s KEV catalog does not diminish its severity. An attacker does not need authentication and must simply reach the vulnerable component from a remote network location; the attack surface is therefore sizable for threats that can reach the Update service.
OpenCVE Enrichment