CVE-2019-3710
DSA-2019-034: Dell EMC Networking OS10 Undocumented Default Cryptographic Key Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying application using undocumented, pre-installed X.509v3 key/certificate pairs. An unauthenticated remote attacker with the knowledge of the default keys may potentially be able to intercept communications or operate the system with elevated privileges.
Las versiones de Dell EMC Networking OS10 anteriores a 10.4.3 contienen una vulnerabilidad de clave criptográfica debido a una aplicación subyacente que utiliza pares de clave/certificado X.509v3 pre-instalados e indocumentados. Un atacante remoto no identificado con el conocimiento de las claves predeterminadas puede potencialmente interceptar comunicaciones u operar el sistema con privilegios elevados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2019-03-28 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.dell.com/support/article/SLN316558 | 2022-04-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Emc Networking Os10 Search vendor "Dell" for product "Emc Networking Os10" | < 10.4.3 Search vendor "Dell" for product "Emc Networking Os10" and version " < 10.4.3" | - |
Affected
|