Improper Authentication Management in Dell EMC Elastic Cloud Storage
CVE-2019-3766

8.1HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
27 September 2019

Summary

Dell EMC Elastic Cloud Storage (ECS) versions prior to 3.4.0.0 are susceptible to a vulnerability that allows an unauthenticated remote attacker to execute a password brute-force attack. This improper restriction on authentication attempts may lead to unauthorized access to targeted accounts, making it essential for organizations to ensure their ECS is updated to mitigate the risks associated with this vulnerability.

Affected Version(s)

Elastic Cloud Storage prior to 3.4.0.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.