Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens which may prove useful to an attacker for crafting malicious authentication tokens for querying the application and subsequent attacks.
References
Link | Resource |
---|---|
https://seclists.org/fulldisclosure/2018/Oct/35 | Mailing List Third Party Advisory |
http://www.securitytracker.com/id/1041877 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/105694 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-10-18 15:29
Updated : 2019-10-09 16:35
NVD link : CVE-2018-15765
Mitre link : CVE-2018-15765
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
dell
- emc_secure_remote_services