{"id":"CVE-2026-49810","published":"2026-09-21T19:17:06.523","lastModified":"2026-09-21T19:17:06.523","description":"Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-532"],"vendors":[],"products":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000502472/dsa-2026-379-security-update-for-dell-command-powershell-provider-dcpp-for-a-credential-theft-via-powershell-event-log-vulnerability","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a low-privileged attacker with local access to insert sensitive information into log files, potentially leading to information disclosure.","exploitability":"Exploitation is moderately difficult requiring local access but straightforward once obtained.","blast_radius":"If exploited, the impact could be significant as it may lead to unauthorized exposure of sensitive data.","remediation":"Update Dell Command Powershell Provider to version 2.10.2 or later immediately.","tags":["info-disc","local-priv","log-exploit"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:10:04.522Z"}}