Dell ESI Vulnerability Allows Unrestricted Access to SAP LAMA
CVE-2023-39244

9.8CRITICAL

Key Information:

Vendor
Dell
Vendor
CVE Published:
15 February 2024

Summary

The DELL Enterprise Storage Integrator (ESI) for SAP Landscape Management (LAMA) version 10.0 is subject to an information disclosure vulnerability within the EHAC component. This vulnerability could allow remote, unauthenticated attackers to gain access to admin-level credentials by eavesdropping on network traffic. Such exploitation poses a significant risk, as it enables unauthorized individuals to intercept sensitive information during communication, potentially compromising the integrity and confidentiality of the system.

Affected Version(s)

ESI (Enterprise Storage Integrator) for SAP LAMA 0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.