CVE-2024-38482 describes an Improper Check or Handling of Exceptional Conditions vulnerability in Dell CloudLink versions 7.1.x and 8.x. A highly privileged remote attacker could exploit this to execute unauthorized actions and exfiltrate sensitive database information. With a CVSS score of 7.2 (High), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Currently, there is no public exploit code (Metasploit, Nuclei, ExploitDB), it is not listed in the KEV catalog, and there is no community discussion or media coverage, indicating no active exploitation or widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.1, < 8.1CPE matchmatch criteria | cpe:2.3:a:dell:cloudlink:*:*:*:*:*:*:*:* | ||
< 8.1CPE match | cpe:2.3:a:dell:cloudlink:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.