CVE-2023-25934: High severity dell emc elastic cloud storage vulnerability
Published May 4, 2023
·Updated
DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify the body data of the request.
Affected Software
1 affected component
Dell Elastic Cloud Storage<3.8.0.2
Event History
May 4, 2023
CVE Published
via MITRE·06:58 AM
Data Sourced
via MITRE·06:58 AM
DescriptionSeverityWeakness
Data Sourced
07:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-25934?
The severity of CVE-2023-25934 is rated as high due to the potential for a network attacker to modify request data.
2
How do I fix CVE-2023-25934?
To fix CVE-2023-25934, upgrade DELL ECS to version 3.8.0.2 or later.
3
What versions are affected by CVE-2023-25934?
CVE-2023-25934 affects all versions of DELL ECS prior to 3.8.0.2.
4
What type of vulnerability is CVE-2023-25934?
CVE-2023-25934 is an improper verification of cryptographic signature vulnerability.
5
Who can exploit CVE-2023-25934?
A network attacker with the ability to intercept requests can exploit CVE-2023-25934.