CVE-2023-23697
Dell Command \| Intel Vpro Out Of Band ≤ 4.4.0
Raw vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HSummary
CVE-2023-23697 is a medium-severity Insecure Operation on Windows Junction / Mount Point (CWE-1386) vulnerability in Dell Command \| Intel Vpro Out Of Band. Its CVSS base score is 4.7 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Path Interception (T1034); ranked at the 7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-27783
Vulnerability Data
Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V5.3.3V15.4.2
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent improper junction/mount-point handling during design and coding.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect junction/mount-point weaknesses before release.
Secure development lifecycle can mandate junction/mount-point validation during design and coding.
Application security requirements can explicitly require protection against Windows reparse-point attacks.
Secure system architecture principles include canonicalization and path-traversal defenses that mitigate junction attacks.
Secure coding standards directly address safe file/directory handling to prevent insecure junction operations.
Information access restriction reduces exposure but does not prevent the technical flaw itself.