CVE-2023-43078

Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.

Published: 2024-08-28 Last update: 2024-12-19 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2023-43078 is rated Low Risk (29.3/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.17%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2023-43078

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.06% 0.17% +0.12%
2 2026-01-17 0.04% 0.06% +0.01%
3 2025-10-07 0.04%

Full EPSS history (5 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2023-43078

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.7 3.1 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.8 5.9 [email protected]
7.3 3.1 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.3 5.9 [email protected]

Weakness enumeration for CVE-2023-43078

Affected software / configurations for CVE-2023-43078

Vendor Product Version Raw CPE
dell intel_thunderbolt_controller_firmware_update_utility < 4.62.156.006 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.66.128.015 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.65.111.022 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.61.124.014 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.46.147.004 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.46.134.013 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.66.131.016 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.46.135.009 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.65.162.003 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.65.119.017 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.62.140.014 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.46.166.001 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.65.163.002 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.62.139.013 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.46.112.015 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.65.116.019 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.46.143.009 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.46.145.004 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.65.117.031 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.62.102.024 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.69.120.013 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.65.108.018 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell intel_thunderbolt_controller_firmware_update_utility < 4.46.106.031 cpe:2.3:a:dell:intel_thunderbolt_controller_firmware_update_utility:*:*:*:*:*:*:*:*
dell tpm_2.0_firmware_update_utility < 7.2.2.0 cpe:2.3:a:dell:tpm_2.0_firmware_update_utility:*:*:*:*:*:*:*:*
dell alienware_m15_r6_firmware < 1.27.0 cpe:2.3:o:dell:alienware_m15_r6_firmware:*:*:*:*:*:*:*:*
dell alienware_m15_r7_firmware < 1.22.0 cpe:2.3:o:dell:alienware_m15_r7_firmware:*:*:*:*:*:*:*:*
dell alienware_m16_r1_firmware < 1.14.1 cpe:2.3:o:dell:alienware_m16_r1_firmware:*:*:*:*:*:*:*:*
dell alienware_m18_r1_firmware < 1.14.1 cpe:2.3:o:dell:alienware_m18_r1_firmware:*:*:*:*:*:*:*:*
dell alienware_x14_r2_firmware < 1.11.0 cpe:2.3:o:dell:alienware_x14_r2_firmware:*:*:*:*:*:*:*:*
dell alienware_x16_r1_firmware < 1.11.0 cpe:2.3:o:dell:alienware_x16_r1_firmware:*:*:*:*:*:*:*:*
dell chengming_3900_firmware < 1.19.0 cpe:2.3:o:dell:chengming_3900_firmware:*:*:*:*:*:*:*:*
dell chengming_3910_firmware < 1.11.0 cpe:2.3:o:dell:chengming_3910_firmware:*:*:*:*:*:*:*:*
dell chengming_3911_firmware < 1.11.0 cpe:2.3:o:dell:chengming_3911_firmware:*:*:*:*:*:*:*:*
dell chengming_3988_firmware < 1.20.0 cpe:2.3:o:dell:chengming_3988_firmware:*:*:*:*:*:*:*:*
dell chengming_3990_firmware < 1.24.0 cpe:2.3:o:dell:chengming_3990_firmware:*:*:*:*:*:*:*:*
dell chengming_3991_firmware < 1.24.0 cpe:2.3:o:dell:chengming_3991_firmware:*:*:*:*:*:*:*:*
dell g15_5510_firmware < 1.22.0 cpe:2.3:o:dell:g15_5510_firmware:*:*:*:*:*:*:*:*
dell g15_5511_firmware < 1.26.0 cpe:2.3:o:dell:g15_5511_firmware:*:*:*:*:*:*:*:*
dell g15_5520_firmware < 1.22.0 cpe:2.3:o:dell:g15_5520_firmware:*:*:*:*:*:*:*:*
dell g15_5530_firmware < 1.12.0 cpe:2.3:o:dell:g15_5530_firmware:*:*:*:*:*:*:*:*
dell g16_7620_firmware < 1.22.0 cpe:2.3:o:dell:g16_7620_firmware:*:*:*:*:*:*:*:*
dell g16_7630_firmware < 1.12.0 cpe:2.3:o:dell:g16_7630_firmware:*:*:*:*:*:*:*:*
dell g3_3500_firmware < 1.28.0 cpe:2.3:o:dell:g3_3500_firmware:*:*:*:*:*:*:*:*
dell g5_5000_firmware < 1.17.0 cpe:2.3:o:dell:g5_5000_firmware:*:*:*:*:*:*:*:*
dell g5_5090_firmware < 1.23.0 cpe:2.3:o:dell:g5_5090_firmware:*:*:*:*:*:*:*:*
dell g5_5500_firmware < 1.28.0 cpe:2.3:o:dell:g5_5500_firmware:*:*:*:*:*:*:*:*
dell g7_7500_firmware < 1.30.0 cpe:2.3:o:dell:g7_7500_firmware:*:*:*:*:*:*:*:*
dell g7_7700_firmware < 1.30.0 cpe:2.3:o:dell:g7_7700_firmware:*:*:*:*:*:*:*:*
dell inspiron_13_5310_firmware < 2.25.0 cpe:2.3:o:dell:inspiron_13_5310_firmware:*:*:*:*:*:*:*:*
dell inspiron_13_5320_firmware < 1.16.0 cpe:2.3:o:dell:inspiron_13_5320_firmware:*:*:*:*:*:*:*:*
dell inspiron_13_5330_firmware < 1.12.1 cpe:2.3:o:dell:inspiron_13_5330_firmware:*:*:*:*:*:*:*:*
dell inspiron_14_5410_firmware < 2.24.0 cpe:2.3:o:dell:inspiron_14_5410_firmware:*:*:*:*:*:*:*:*
dell inspiron_14_5418_firmware < 2.24.0 cpe:2.3:o:dell:inspiron_14_5418_firmware:*:*:*:*:*:*:*:*
dell inspiron_14_5420_firmware < 1.19.0 cpe:2.3:o:dell:inspiron_14_5420_firmware:*:*:*:*:*:*:*:*
dell inspiron_14_5430_firmware < 1.11.0 cpe:2.3:o:dell:inspiron_14_5430_firmware:*:*:*:*:*:*:*:*
dell inspiron_14_7420_2-in-1_firmware < 1.17.0 cpe:2.3:o:dell:inspiron_14_7420_2-in-1_firmware:*:*:*:*:*:*:*:*
dell inspiron_14_7430_2-in-1_firmware < 1.11.0 cpe:2.3:o:dell:inspiron_14_7430_2-in-1_firmware:*:*:*:*:*:*:*:*
dell inspiron_14_plus_7420_firmware < 1.20.0 cpe:2.3:o:dell:inspiron_14_plus_7420_firmware:*:*:*:*:*:*:*:*
dell inspiron_14_plus_7430_firmware < 1.12.0 cpe:2.3:o:dell:inspiron_14_plus_7430_firmware:*:*:*:*:*:*:*:*
dell inspiron_15_3511_firmware < 1.26.0 cpe:2.3:o:dell:inspiron_15_3511_firmware:*:*:*:*:*:*:*:*
dell inspiron_15_3520_firmware < 1.22.0 cpe:2.3:o:dell:inspiron_15_3520_firmware:*:*:*:*:*:*:*:*
dell inspiron_15_3530_firmware < 1.8.0 cpe:2.3:o:dell:inspiron_15_3530_firmware:*:*:*:*:*:*:*:*
dell inspiron_15_5510_firmware < 2.24.0 cpe:2.3:o:dell:inspiron_15_5510_firmware:*:*:*:*:*:*:*:*
dell inspiron_15_5518_firmware < 2.24.0 cpe:2.3:o:dell:inspiron_15_5518_firmware:*:*:*:*:*:*:*:*
dell inspiron_15_7510_firmware < 1.20.0 cpe:2.3:o:dell:inspiron_15_7510_firmware:*:*:*:*:*:*:*:*
dell inspiron_16_5620_firmware < 1.19.0 cpe:2.3:o:dell:inspiron_16_5620_firmware:*:*:*:*:*:*:*:*
dell inspiron_16_5630_firmware < 1.11.0 cpe:2.3:o:dell:inspiron_16_5630_firmware:*:*:*:*:*:*:*:*
dell inspiron_16_7610_firmware < 1.20.0 cpe:2.3:o:dell:inspiron_16_7610_firmware:*:*:*:*:*:*:*:*
dell inspiron_16_7620_2-in-1_firmware < 1.17.0 cpe:2.3:o:dell:inspiron_16_7620_2-in-1_firmware:*:*:*:*:*:*:*:*
dell inspiron_16_7630_2-in-1_firmware < 1.11.0 cpe:2.3:o:dell:inspiron_16_7630_2-in-1_firmware:*:*:*:*:*:*:*:*
dell inspiron_16_plus_7620_firmware < 1.20.0 cpe:2.3:o:dell:inspiron_16_plus_7620_firmware:*:*:*:*:*:*:*:*
dell inspiron_16_plus_7630_firmware < 1.12.0 cpe:2.3:o:dell:inspiron_16_plus_7630_firmware:*:*:*:*:*:*:*:*
dell inspiron_24_5410_all-in-one_firmware < 1.18.0 cpe:2.3:o:dell:inspiron_24_5410_all-in-one_firmware:*:*:*:*:*:*:*:*
dell inspiron_24_5411_all-in-one_firmware < 1.18.0 cpe:2.3:o:dell:inspiron_24_5411_all-in-one_firmware:*:*:*:*:*:*:*:*
dell inspiron_24_5420_all-in-one_firmware < 1.8.0 cpe:2.3:o:dell:inspiron_24_5420_all-in-one_firmware:*:*:*:*:*:*:*:*
dell inspiron_27_7710_all-in-one_firmware < 1.18.0 cpe:2.3:o:dell:inspiron_27_7710_all-in-one_firmware:*:*:*:*:*:*:*:*
dell inspiron_27_7720_all-in-one_firmware < 1.8.0 cpe:2.3:o:dell:inspiron_27_7720_all-in-one_firmware:*:*:*:*:*:*:*:*
dell inspiron_3020_desktop_firmware < 1.11.0 cpe:2.3:o:dell:inspiron_3020_desktop_firmware:*:*:*:*:*:*:*:*
dell inspiron_3020_small_desktop_firmware < 1.11.0 cpe:2.3:o:dell:inspiron_3020_small_desktop_firmware:*:*:*:*:*:*:*:*
dell inspiron_3471_firmware < 1.20.0 cpe:2.3:o:dell:inspiron_3471_firmware:*:*:*:*:*:*:*:*

References for CVE-2023-43078

cvelogic Threat Intelligence