Critical Flaw in Dell Power Manager Exposes Systems to Unauthorized Access – Urgent Update Required!

Dell Technologies has discovered a security flaw in Dell Power Manager (DPM), impacting all versions up to and including 3.15.0.

The flaw, tracked as CVE-2024-39576, pertains to an Incorrect Privilege Assignment. This issue could be exploited by a locally situated attacker with limited privileges, enabling them to execute code and potentially escalate their access rights.

Vulnerability Overview

This security vulnerability, CVE-2024-39576, was uncovered by Lefteris Panos from LRQA Nettitude. It involves an Incorrect Privilege Assignment in Dell Power Manager, which could be leveraged by a low-privileged user with local access to execute arbitrary code and gain higher privileges.

If exploited successfully, this vulnerability may lead to unauthorized code execution and privilege escalation on the compromised system. The issue has been rated with a CVSS Base Score of 8.8, reflecting its high severity, and is detailed by the CVSS vector string CVSS:3.1.

The vulnerability affects Dell Power Manager versions earlier than 3.16.0. Users are urged to upgrade their software to the latest version to avoid potential security risks.

“Dell Power Manager (DPM) versions 3.15.0 and earlier are susceptible to an Incorrect Privilege Assignment vulnerability. A low-privileged local attacker could exploit this vulnerability to execute code and escalate privileges,” according to Dell’s release notes.
Workarounds & Mitigations

Currently, there are no available workarounds or alternative mitigations for this security issue. Dell Technologies strongly advises updating to the latest version to address the vulnerability.

Affected Products:

  • Product: Dell Power Manager
  • Software/Firmware: Versions before 3.16.0
  • Remediated Version: Dell Power Manager version 3.16.0 or later

Dell Technologies encourages all users to review the CVSS base score and consider any relevant temporal and environmental factors that might affect the overall risk associated with this security vulnerability.

More Articles & Posts