CVE-2023-28051
Description
Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell Power Manager versions 3.10 and prior have an improper access control flaw that lets low-privileged attackers elevate privileges.
Vulnerability
Dell Power Manager versions 3.10 and prior contain an Improper Access Control vulnerability (CVE-2023-28051). The issue lies in the software's access control mechanisms, which fail to properly enforce restrictions, allowing a low-privileged attacker to interact with functions or objects that should require higher privileges [1].
Exploitation
An attacker with low-privileged user access to the local system can exploit this vulnerability without user interaction (UI:N) and without needing any special timing or race conditions. The attack vector is local (AV:L), and the required privileges are low (PR:L). No network access is needed, and the attack complexity is low (AC:L) [1].
Impact
Successful exploitation allows the attacker to elevate privileges on the system, leading to a full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). The CVSS base score is 7.8, indicating high severity [1].
Mitigation
Dell released version 3.11 of Power Manager to address this vulnerability, available for download at the Dell support site [1]. Users should update to version 3.11 or later. No workarounds or mitigations are provided for unpatched versions [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=3.10
- Dell/Dell Power Manager (DPM)v5Range: Versions 3.10 and prior
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/en-us/000211891/dsa-2023-221-dell-power-managermitrevendor-advisory
News mentions
0No linked articles in our index yet.