CVE-2019-3746: Critical severity dell emc integrated data protection appliance firmware vulnerability
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticated remote user may exploit this vulnerability to launch a brute-force authentication attack in order to gain access to the system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Dell EMC Integrated Data Protection Appliance vulnerability?
The vulnerability ID for this Dell EMC Integrated Data Protection Appliance vulnerability is CVE-2019-3746.
What is the severity level of CVE-2019-3746?
CVE-2019-3746 has a severity level of 8.8 (Critical).
How does CVE-2019-3746 affect Dell EMC Integrated Data Protection Appliance versions prior to 2.3?
CVE-2019-3746 allows an authenticated remote user to launch a brute-force authentication attack in order to gain access to the system on Dell EMC Integrated Data Protection Appliance versions prior to 2.3.
Which versions of Dell EMC Integrated Data Protection Appliance are affected by CVE-2019-3746?
Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 are affected by CVE-2019-3746.
How can I fix CVE-2019-3746?
To fix CVE-2019-3746, update the Dell EMC Integrated Data Protection Appliance firmware to version 2.3 or later.