CVE-2024-52543
MEDIUMDell Nativeedge Orchestrator < 2.2.0.0 - Information Disclosure
Title source: ruleDescription
Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Scores
CVSS v3
6.5
EPSS
0.0002
EPSS Percentile
4.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-378
CWE-668
Status
published
Affected Products (1)
dell/nativeedge_orchestrator
< 2.2.0.0
Timeline
Published
Dec 25, 2024
Tracked Since
Feb 18, 2026