CVE-2024-28976

HIGH

Dell Repository Manager < 3.4.5 - Path Traversal in API Module

Title source: llm
STIX 2.1

Description

Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized write access to the files stored on the server filesystem with the privileges of the running web application.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 18.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-20
Status published
Products (1)
dell/repository_manager < 3.4.5
Published Apr 24, 2024
Tracked Since Feb 18, 2026