First published: Fri Jun 28 2024(Updated: )
Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to privileged information disclosure.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Key Trust Platform | <3.0.6 | |
Dell EMC Cloud Link | <7.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37137 is considered a medium severity vulnerability that could allow local privileged attackers to disclose sensitive information.
To fix CVE-2024-37137, update the Dell Key Trust Platform to version 3.0.7 or later.
CVE-2024-37137 could potentially allow privileged attackers to access sensitive information stored within the affected application.
CVE-2024-37137 affects Dell Key Trust Platform versions up to and including 3.0.6.
Yes, Dell CloudLink is also vulnerable to CVE-2024-37137, specifically up to version 7.1.9.