CVE-2024-28974: Weak Encryption
Published May 29, 2024
·Updated
Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
Affected Software
6 affected components
Dell Data Protection Advisor
Dell Data Protection Advisor>=19.5<19.9
All of the following
Dell Dp4400 Firmware<=2.7.6
Dell Dp4400
All of the following
Dell Dp5900 Firmware<=2.7.6
Dell Dp5900
Event History
May 29, 2024
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28974?
CVE-2024-28974 is categorized with a low severity level.
2
How do I fix CVE-2024-28974?
To mitigate CVE-2024-28974, update your Dell Data Protection Advisor to a version that is newer than 19.9.
3
Who can exploit CVE-2024-28974?
CVE-2024-28974 can be exploited by a low privileged attacker with remote access.
4
What is the impact of CVE-2024-28974?
The impact of CVE-2024-28974 may lead to a Denial of Service condition.
5
Which versions of Dell software are affected by CVE-2024-28974?
CVE-2024-28974 affects Dell Data Protection Advisor versions up to 19.9.