Brute Force Vulnerability in Dell EMC Integrated Data Protection Appliance
CVE-2019-3746
9.8CRITICAL
Key Information:
- Vendor
Dell
- Vendor
- CVE Published:
- 27 September 2019
What is CVE-2019-3746?
The Dell EMC Integrated Data Protection Appliance versions prior to 2.3 are susceptible to a brute-force authentication attack due to a lack of limit on authentication attempts to the ACM API. This allows an authenticated remote user to exploit the failure to restrict multiple login attempts, potentially leading to unauthorized access to sensitive system areas.
Affected Version(s)
Integrated Data Protection Appliance prior to 2.3