Headline
CVE-2023-3039: DSA-2023-274: Security Update for an SD ROM Utility Vulnerability
SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit this vulnerability to perform arbitrary code execution with limited access.
Impact
High
Details
Proprietary Code CVEs
Description
CVSS Base Score
CVSS Vector String
CVE-2023-3039
SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit this vulnerability to perform arbitrary code execution with limited access.
7.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Proprietary Code CVEs
Description
CVSS Base Score
CVSS Vector String
CVE-2023-3039
SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit this vulnerability to perform arbitrary code execution with limited access.
7.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
Affected Products and Remediation
Product
Software/Firmware
Affected Versions
Remediated Versions
Link
SD ROM Utility
Software
Versions prior to 1.0.2.0
1.0.2.0 or later
https://www.dell.com/support/home/drivers/driversdetails?driverid=HC20P
Product
Software/Firmware
Affected Versions
Remediated Versions
Link
SD ROM Utility
Software
Versions prior to 1.0.2.0
1.0.2.0 or later
https://www.dell.com/support/home/drivers/driversdetails?driverid=HC20P
Workarounds and Mitigations
None.
Revision History
Revision
Date
Description
1.0
2023-09-11
Initial Release
Related Information
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide
Update Packages, 5820 XL Tower, 7820 XL Tower, 7920 XL Tower, Precision 7520, Precision 7720, Precision 5820 Tower, Precision 7820 Tower, Precision 7920 Tower