---
id: CVE-2024-37129
title: >-
  Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal
  vulnerability
summary: >-
  Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal
  vulnerability. A local authenticated malicious user could potentially exploit
  this vulnerability, leading to arbitrary code execution on the system.
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-22
vendor: dell
product: inventory_collector
affected:
  - inventory_collector < 12.3.0.6
patched:
  - inventory_collector 12.3.0.6
published: '2024-07-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-37129'
references:
  - url: 'https://www.dell.com/support/kbdoc/en-us/000225779/dsa-2024-263'
    label: security_alert@emc.com
tags:
  - nvd
epss: 0.0017
epssPercentile: 0.06688
ingestedAt: '2026-07-24T13:28:03.414Z'
---

## Overview

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.

## Affected

- `inventory_collector < 12.3.0.6`

## Remediation

Upgrade past the affected range:

- `inventory_collector 12.3.0.6`
