Dell Command Update, Dell Update, and Alienware Update versions prior to 4.3 contains a Improper Certificate Verification vulnerability. A local authenticated malicious user could exploit this vulnerability by modifying local configuration files in order to execute arbitrary code on the system.
References
| Link | Resource |
|---|---|
| https://www.dell.com/support/kbdoc/en-us/000190110 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-08-09 21:15
Updated : 2021-08-17 17:45
NVD link : CVE-2021-36277
Mitre link : CVE-2021-36277
JSON object : View
Products Affected
dell
- update\/alienware_update
- command_\|_update
CWE
CWE-347
Improper Verification of Cryptographic Signature
