CVE-2024-28977

LOW

Dell Repository Manager 3.4.2-3.4.4 - Path Traversal in Logger Module

Title source: llm
STIX 2.1

Description

Dell Repository Manager, versions 3.4.2 through 3.4.4,contains a Path Traversal vulnerability in logger module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem with the privileges of the running web application.

Scores

CVSS v3 3.3
EPSS 0.0006
EPSS Percentile 17.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-20
Status published
Products (1)
dell/repository_manager 3.4.2 - 3.4.4
Published Apr 24, 2024
Tracked Since Feb 18, 2026