VYPR
Unrated severityNVD Advisory· Published Dec 3, 2024· Updated Dec 3, 2024

CVE-2024-42422

CVE-2024-42422

Description

Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell NetWorker Client versions prior to 19.10.0.6 and 19.11 through 19.11.0.2 are vulnerable to an authorization bypass via user-controlled key, allowing unauthenticated remote information disclosure.

Vulnerability

Dell NetWorker Client contains an Authorization Bypass Through User-Controlled Key vulnerability (CWE-639). Affected versions are those prior to 19.10.0.6 and versions 19.11 through 19.11.0.2. The flaw resides in the client component and allows an attacker to manipulate a key used for authorization checks, thereby bypassing access controls [1].

Exploitation

An unauthenticated attacker with remote network access can exploit this vulnerability by sending specially crafted requests that control the authorization key. No authentication or user interaction is required. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L indicates low attack complexity and no privileges needed [1].

Impact

Successful exploitation results in information disclosure (low confidentiality impact), as well as low integrity and availability impacts. The attacker can gain unauthorized read access to sensitive data and potentially perform limited modifications or cause service disruption [1].

Mitigation

Dell has released fixed versions: 19.10.0.6 and 19.11.0.3 or later. Users should upgrade to these versions. No workarounds are provided in the advisory [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.