Sceawere
Vulnerability Detail
CVE-2026-82163UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell Command Incorrect Permissions Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 2h ago
- Vendor
- Dell
- Product
- Command | Intel vPro Out of Band
- Attack Type
- CWE-276: Incorrect Default Permissions
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-21T19:17:11.580Z",
"pubdate": "2026-09-21T19:17:11.580Z",
"executiveSummary": "Dell Command | Intel vPro Out of Band versions prior to 4.7.2 are affected by an Incorrect Default Permissions vulnerability. This security flaw allows a low-privileged local attacker to gain unauthorized access to sensitive data, leading to Information Disclosure.\nThe vulnerability originates from improper access control settings applied to system resources during installation or operation. By exploiting these weak permissions, a local user can bypass standard security boundaries to read protected information that should be inaccessible at their current privilege level.\nThe risk is categorized as significant because it lowers the barrier for internal reconnaissance or credential harvesting by unauthorized local entities. No remote network interaction is required for this exploit, as it relies on local system access. Organizations utilizing affected versions of Dell Command | Intel vPro Out of Band should prioritize the update to version 4.7.2 or later to enforce correct permission inheritance and security boundaries.",
"technicalDetails": "The vulnerability is classified as an Incorrect Default Permissions issue, specifically manifesting when the application fails to restrict file system or registry access correctly during its deployment or execution lifecycle. In the context of Dell Command | Intel vPro Out of Band, the vulnerable component establishes security descriptors that are overly permissive, granting 'Read' or 'Execute' access to low-privileged local user accounts that should otherwise be restricted.\nThe root cause lies in the misconfiguration of Access Control Lists (ACLs) associated with sensitive files or memory objects managed by the Intel vPro Out of Band service. Because the application processes or configuration files are reachable by non-administrative users, the system fails to maintain the principle of least privilege.\nThe attack flow proceeds as follows: First, a low-privileged user authenticated on the local host identifies the target file path or object protected by the vulnerable component. Second, the attacker leverages the lack of enforced security constraints to perform unauthorized read operations on these objects. Because the underlying operating system honors the loose ACLs set by the application, the attacker successfully exfiltrates sensitive information—such as configuration parameters, session tokens, or other proprietary metadata—without triggering access violation errors.\nExploitation does not require elevated privileges or administrative tokens; it requires only that the attacker has local interactive or programmatic access to the host machine. The lack of network exposure means this attack is inherently restricted to the local environment, yet its impact is critical in multi-user or shared-infrastructure environments where lateral movement or local data discovery is a primary objective. The post-exploitation state involves the acquisition of sensitive system intelligence that can be weaponized for subsequent privilege escalation or further attacks against the vPro management infrastructure. Version 4.7.2 corrects this by explicitly hardening the ACLs and ensuring that proper inheritance is applied to all sensitive configuration and data files associated with the Intel vPro Out of Band component."
}