CVE-2024-38482

MEDIUM

CloudLink <8 - Privilege Escalation

Title source: llm
STIX 2.1

Description

CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote access could potentially exploit this vulnerability, leading to execute unauthorized actions and retrieve sensitive information from the database.

Scores

CVSS v3 6.6
EPSS 0.0037
EPSS Percentile 28.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-703
Status published
Products (1)
dell/cloudlink 7.1 - 8.1
Published Aug 02, 2024
Tracked Since Feb 18, 2026