Information Disclosure in Dell OpenManage Enterprise by Dell
CVE-2021-21584
7.7HIGH
Summary
Dell OpenManage Enterprise versions 3.5 and OpenManage Enterprise-Modular version 1.30.00 are susceptible to an information disclosure vulnerability. This issue could allow an authenticated attacker with low privileges to exploit the system, leading to the unauthorized disclosure of sensitive OIDC server credentials. As a result, an attacker could gain access to critical information that may compromise the integrity and security of the affected servers.
Affected Version(s)
Dell OpenManage Enterprise < 3.6.1
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved