CVE-2024-38482

MEDIUM

CloudLink <8 - Privilege Escalation

Title source: llm
STIX 2.1

Description

CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote access could potentially exploit this vulnerability, leading to execute unauthorized actions and retrieve sensitive information from the database.

Scores

CVSS v3 6.6
EPSS 0.0047
EPSS Percentile 64.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-703
Status published
Products (1)
dell/cloudlink 7.1 - 8.1
Published Aug 02, 2024
Tracked Since Feb 18, 2026