Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some sensitive encrypted information in the images it creates. A privileged user of a system running an operating system that was deployed with Dell ImageAssist could potentially retrieve this sensitive information to then compromise the system and related systems.
References
Link | Resource |
---|---|
https://www.dell.com/support/article/us/en/19/sln318831/dsa-2019-139 | Vendor Advisory |
Configurations
Information
Published : 2019-10-14 11:15
Updated : 2020-10-16 07:19
NVD link : CVE-2019-3767
Mitre link : CVE-2019-3767
JSON object : View
CWE
CWE-312
Cleartext Storage of Sensitive Information
Products Affected
dell
- imageassist