Home
HIGH: 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
NA (semver) before 11.11.0.1
affected
Default status
unaffected
NA (semver) before 11.11.0.2
affected
Description
Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.
Problem types
CWE-59: Improper Link Resolution Before File Access ('Link Following')
Product status
NA (semver) before 11.11.0.1
NA (semver) before 11.11.0.2
Credits
Dell would like to thank falconCorrup for reporting this issue.
References
www.dell.com/support/kbdoc/en-us/000347824/dsa-2025-292