Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22433

Опубликовано: 06 фев. 2024
Источник: nvd
CVSS3: 8.8
CVSS3: 9.8
EPSS Низкий

Описание

Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of Confidentiality, Integrity, Protection, and remote takeover of the system. This is a high-severity vulnerability as it allows an attacker to take complete control of DP Search to affect downstream protected devices.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dell:data_protection_search:*:*:*:*:*:*:*:*
Версия от 19.2.0 (включая) до 19.6.4 (исключая)

EPSS

Процентиль: 45%
0.00224
Низкий

8.8 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-538
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.8
github
около 2 лет назад

Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of Confidentiality, Integrity, Protection, and remote takeover of the system. This is a high-severity vulnerability as it allows an attacker to take complete control of DP Search to affect downstream protected devices.

CVSS3: 9.8
fstec
около 2 лет назад

Уязвимость компонента LdapSettings.get_ldap_info системы комплексной защиты данных Dell Data Protection Search, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 45%
0.00224
Низкий

8.8 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-538
NVD-CWE-noinfo