Dell ESI Vulnerability Allows Unrestricted Access to SAP LAMA
CVE-2023-39244
9.8CRITICAL
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 15 February 2024
Summary
The DELL Enterprise Storage Integrator (ESI) for SAP Landscape Management (LAMA) version 10.0 is subject to an information disclosure vulnerability within the EHAC component. This vulnerability could allow remote, unauthenticated attackers to gain access to admin-level credentials by eavesdropping on network traffic. Such exploitation poses a significant risk, as it enables unauthorized individuals to intercept sensitive information during communication, potentially compromising the integrity and confidentiality of the system.
Affected Version(s)
ESI (Enterprise Storage Integrator) for SAP LAMA 0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved