CVE-2024-28972
https://notcve.org/view.php?id=CVE-2024-28972
Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure. Dell InsightIQ, versión 5.0.0, contiene una vulnerabilidad relacionada con el uso de un algoritmo criptográfico dañado o riesgoso. Un atacante remoto no autenticado podría aprovechar esta vulnerabilidad y provocar la divulgación de información. • https://www.dell.com/support/kbdoc/en-us/000226567/dsa-2024-211-security-update-for-a-dell-insightiq-broken-or-risky-cryptographic-algorithm-vulnerability • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2024-25962
https://notcve.org/view.php?id=CVE-2024-25962
Dell InsightIQ, version 5.0, contains an improper access control vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to monitoring data. Dell InsightIQ, versión 5.0, contiene una vulnerabilidad de control de acceso inadecuado. Un atacante remoto con pocos privilegios podría explotar esta vulnerabilidad, lo que daría lugar a un acceso no autorizado a los datos de supervisión. • https://www.dell.com/support/kbdoc/en-us/000223551/dsa-2024-134-security-update-for-dell-insightiq-for-proprietary-code-vulnerability • CWE-284: Improper Access Control •
CVE-2021-36298
https://notcve.org/view.php?id=CVE-2021-36298
Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component. A remote unauthenticated attacker could potentially exploit this vulnerability leading to authentication bypass and remote takeover of the InsightIQ. This allows an attacker to take complete control of InsightIQ to affect services provided by SSH; so Dell recommends customers to upgrade at the earliest opportunity. Dell EMC InsightIQ versiones anteriores a 4.1.4, contienen algoritmos criptográficos arriesgados en el componente SSH. Un atacante remoto no autenticado podría potencialmente explotar esta vulnerabilidad conllevando a una omisión de la autenticación y a la toma remota del InsightIQ. • https://www.dell.com/support/kbdoc/000191604 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •