CVE-2019-3736: High severity dell emc integrated data protection appliance firmware vulnerability
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other components using the privileges of the compromised user.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-3736.
What is the severity of CVE-2019-3736?
The severity of CVE-2019-3736 is high with a severity value of 7.2.
What is the affected software?
The affected software is Dell EMC Integrated Data Protection Appliance versions prior to 2.3.
What is the description of the vulnerability?
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component.
How can a remote authenticated malicious user exploit this vulnerability?
A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to ac…