Echo: dmidecode: security update to 3.6

high Tenable Cloud Security Plugin ID 464924

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for
example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in
3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents
dmidecode from writing to an existing file. However, there are multiple attack vectors that would not
require overwriting an existing file that would provide the same level of unauthorized privilege
escalation (e.g. creating a new file in /etc/cron.hourly). (CVE-2023-30630)

Solution

Update the dmidecode library and its related packages to version 3.6 or later.

See Also

https://advisory.echohq.com/cve/CVE-2023-30630

Plugin Details

Severity: High

ID: 464924

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.04

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

CVSS Score Source: CVE-2023-30630

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 4/13/2023

Reference Information

CVE: CVE-2023-30630