{"id":"CVE-2024-22451","title":"Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability","summary":"Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious executable, leading to arbitrary code…","severity":"medium","cvss":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-427"],"vendor":"dell","product":"peripheral_manager","affected":["peripheral_manager >= 1.5.1, < 1.7.3"],"patched":["peripheral_manager 1.7.3"],"published":"2026-06-16","updated":"2026-10-02","sourceUpdated":"2026-10-02T00:10:00.180","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-22451","references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000221413/dsa-2024-055-security-update-for-dell-peripheral-manager-uncontrolled-search-path-element-vulnerabilities?lang=en","label":"security_alert@emc.com"}],"tags":["nvd"],"epss":0.00099,"epssPercentile":0.00761,"ingestedAt":"2026-10-02T01:05:54.719Z","slug":"CVE-2024-22451","body":"## Overview\n\nDell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious executable, leading to arbitrary code execution.\n\n## Affected\n\n- `peripheral_manager >= 1.5.1, < 1.7.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `peripheral_manager 1.7.3`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":36.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}