Sceawere

Vulnerability Detail

CVE-2026-49810UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DCPP Sensitive Information Log Exposure

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
2h ago
Vendor
Dell
Product
Command Powershell Provider (DCPP)
Attack Type
CWE-532: Insertion of Sensitive Information into Log File
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-09-21T19:17:06.523Z",
  "pubdate": "2026-09-21T19:17:06.523Z",
  "executiveSummary": "Dell Command PowerShell Provider (DCPP) versions prior to 2.10.2 are susceptible to an Insertion of Sensitive Information into Log File vulnerability. This security flaw allows for the unauthorized disclosure of sensitive data through improper logging practices within the application.\nThe vulnerability affects local systems where DCPP is deployed. An attacker possessing low-privileged local access can leverage this exposure to gain insight into protected information that may be inadvertently written to logs during operation.\nThe risk implication centers on Information Disclosure, which can facilitate further malicious activities such as privilege escalation or lateral movement if the leaked data includes credentials, configuration secrets, or system-specific identifiers.\nExploitation requires the attacker to have established local access to the target host. No network exposure is required, as the vulnerability is restricted to local log file analysis by an unauthorized user.",
  "technicalDetails": "The vulnerability is categorized as an Insertion of Sensitive Information into Log File, resulting from the application's failure to sanitize or filter sensitive data before committing it to persistent storage in log files.\nThe affected component is the Dell Command PowerShell Provider (DCPP), specifically versions prior to 2.10.2. The root cause lies in the application's logging logic, which likely captures runtime parameters, session tokens, or internal system configurations that should remain obfuscated or excluded from administrative logs.\nThe attack flow proceeds as follows: First, an attacker with low-privileged local access to the host identifies the specific directory where the DCPP logs are stored. Given that these logs are typically generated during the standard execution of PowerShell cmdlets provided by the DCPP module, the application may log verbosely to assist in troubleshooting.\nSecond, the attacker triggers specific DCPP functions or cmdlets that are known to process sensitive inputs or retrieve system configurations. As the application executes these operations, the sensitive data is processed in memory and subsequently committed to the log file by the logging utility.\nThird, once the information is written to the log file, the attacker utilizes standard filesystem read permissions—if the log files lack sufficient access control restrictions—to parse the content. The disclosure occurs because the application improperly treats sensitive data as non-sensitive debug or operational metadata.\nPost-exploitation impact involves the recovery of sensitive information that can be utilized to compromise the broader security posture of the host. If the logs contain credentials used by DCPP for BIOS or hardware management, the attacker could theoretically reuse these secrets to perform unauthorized hardware-level modifications or bypass security controls implemented via BIOS policies. Because the vulnerability requires local access, the attacker is assumed to have an existing foothold on the target operating system. The lack of proper log rotation or ACL enforcement on these log files further exacerbates the risk, as it allows even low-privileged entities to aggregate historical data that may contain multiple instances of sensitive disclosures over an extended period."
}
CVE-2026-49810: DCPP Sensitive Information Log Exposure (HIGH Severity, CVSS: 7.8) | Sceawere