CVE-2024-22433
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of Confidentiality, Integrity, Protection, and remote takeover of the system. This is a high-severity vulnerability as it allows an attacker to take complete control of DP Search to affect downstream protected devices.
Dell Data Protection Search 19.2.0 y versiones posteriores contienen una oportunidad de contraseña expuesta en texto plano cuando se usa LdapSettings.get_ldap_info en DP Search. Un atacante remoto no autorizado y no autenticado podría explotar esta vulnerabilidad, lo que provocaría una pérdida de confidencialidad, integridad, protección y toma de control remoto del sistema. Esta es una vulnerabilidad de alta gravedad, ya que permite a un atacante tomar el control total de DP Search para afectar los dispositivos protegidos posteriores.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-01-10 CVE Reserved
- 2024-02-01 CVE Published
- 2024-02-14 EPSS Updated
- 2024-08-19 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.dell.com/support/kbdoc/en-us/000221720/dsa-2024-063-security-update-for-dell-data-protection-search-multiple-security-vulnerabilities | 2024-02-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Data Protection Search Search vendor "Dell" for product "Data Protection Search" | >= 19.2.0 < 19.6.4 Search vendor "Dell" for product "Data Protection Search" and version " >= 19.2.0 < 19.6.4" | - |
Affected
|