boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-43086

Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0022   11.4     —
AFFECTED
  Product                       Versions                    Fixed
  Dell Command Configure (DCC)  Versions prior to 4.11.0 –  —
TIMELINE
  Sep 15  Reserved by dell
  Nov 23  Published (CNA: dell)
  Oct 7   RESCORED — CVE-2023-43086 (Dell Command Configure (DCC)). CVSS 7.3 → 7.8 (NVD).
CWE-284 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Modified

Description

Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local malicious user could potentially modify files inside installation folder during application upgrade, leading to privilege escalation.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 15, 2023ReservedReserved by dell
November 23, 2023PublishedPublished (CNA: dell)
October 7, 2026RESCOREDRESCORED — CVE-2023-43086 (Dell Command Configure (DCC)). CVSS 7.3 → 7.8 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
DellDell Command Configure (DCC)—Versions prior to 4.11.0—

Weaknesses

CWE-284

References (1)

Related

Authoritative record: CVE-2023-43086 at cve.org

Vendors: dell

Weaknesses: CWE-284

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-43086 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.