Vulnerability Description
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other components using the privileges of the compromised user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Emc Integrated Data Protection Appliance Firmware | 2.0 |
| Dell | Emc Idpa Dp4400 | - |
| Dell | Emc Idpa Dp5800 | - |
| Dell | Emc Idpa Dp8300 | - |
| Dell | Emc Idpa Dp8800 | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/security/en-us/details/536363/DSA-2019-112-Dell-EMCVendor Advisory
- https://www.dell.com/support/security/en-us/details/536363/DSA-2019-112-Dell-EMCVendor Advisory
FAQ
What is CVE-2019-3736?
CVE-2019-3736 is a vulnerability with a CVSS score of 7.2 (HIGH). Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potent...
How severe is CVE-2019-3736?
CVE-2019-3736 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-3736?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Emc Integrated Data Protection Appliance Firmware, Dell Emc Idpa Dp4400, Dell Emc Idpa Dp5800, Dell Emc Idpa Dp8300, Dell Emc Idpa Dp8800.