ZeroHour

CVE-2019-3736

CVSS 3.1
7.2 high
EPSS
<1%p51
Published
()
Modified
Description

Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other components using the privileges of the compromised user.

Vendors
dell
Products
emc integrated data protection appliance firmware
Weakness
CWE-257, CWE-327
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.