CVE-2026-49810
7.8Dell · Command Powershell Provider (DCPP)
Dell Command Powershell Provider (DCPP) versions prior to 2.10.2 contain an insertion of sensitive information into log files, allowing local attackers to potentially access sensitive data.
Executive summary
A vulnerability in Dell Command Powershell Provider (DCPP) allows a low privileged local attacker to access sensitive information through insecure log files, presenting a significant data leakage risk.
Vulnerability
The application is susceptible to CWE-532, which involves the improper storage of sensitive information within system log files. An attacker with low privileges and local access can exploit this flaw to read sensitive data that should not be exposed to non-administrative users.
Business impact
Successful exploitation allows unauthorized access to sensitive information, which could include credentials or configuration data, leading to potential privilege escalation or lateral movement within the environment. With a CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the significant impact on confidentiality, integrity, and availability if sensitive credentials are harvested from the logs.
Remediation
Immediate Action: Update Dell Command Powershell Provider (DCPP) to version 2.10.2 or later as specified in the vendor security advisory.
Proactive Monitoring: Audit local system log files for unexpected access patterns and monitor for any unauthorized attempts to read sensitive directories or log locations.
Compensating Controls: Restrict local user permissions to prevent unauthorized access to system logs and sensitive configuration files, adhering to the principle of least privilege.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for credential exposure, organizations should prioritize patching Dell Command Powershell Provider (DCPP) across all affected endpoints. IT administrators should verify that the update to version 2.10.2 is deployed to prevent local attackers from leveraging this information disclosure flaw to compromise system security.
More Dell CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Dell would like to thank saltedfish for reporting this issue., per the CVE Program record.