CVE-2019-3767 HIGH

CVE-2019-3767

Vendor Dell
Product ImageAssist
Weakness CWE-200 · Info exposure
Published October 14, 2019
Last update September 17, 2024

CVSS base score

7.5/10
Attack vector Local
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some sensitive encrypted information in the images it creates. A privileged user of a system running an operating system that was deployed with Dell ImageAssist could potentially retrieve this sensitive information to then compromise the system and related systems.

Key dates

02Disclosure timeline

October 14, 2019 CVE published
September 17, 2024 Record updated