First published: Sun Oct 18 2015(Updated: )
EMC SourceOne Email Supervisor before 7.2 uses hardcoded encryption keys, which makes it easier for attackers to obtain access by examining how a program's code conducts cryptographic operations.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC SourceOne | <=7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6846 has a medium severity level due to the risk posed by hardcoded encryption keys.
To fix CVE-2015-6846, upgrade EMC SourceOne Email Supervisor to version 7.2 or later where the vulnerability is addressed.
The potential impacts of CVE-2015-6846 include unauthorized access to sensitive information due to the compromised encryption keys.
CVE-2015-6846 affects EMC SourceOne Email Supervisor versions prior to 7.2, specifically versions up to 7.1.
Organizations using EMC SourceOne Email Supervisor versions before 7.2 should be concerned about CVE-2015-6846 and take necessary actions to mitigate risks.