Data Protection Search Vulnerability in Dell Products
CVE-2024-22433

9.8CRITICAL

Key Information:

Vendor
Dell
Vendor
CVE Published:
1 February 2024

Summary

A serious security concern has been identified within Dell Data Protection Search versions 19.2.0 and above. The vulnerability arises from exposed passwords in plain text when accessing LDAP settings through the function LdapSettings.get_ldap_info. This flaw enables unauthorized remote attackers to gain access to sensitive information. Such an exploit could lead to significant breaches, including unauthorized system control, loss of confidentiality, and integrity of protected data. Organizations using affected versions should prioritize applying security updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Data Protection Search 19.2.0

Data Protection Search 19.3.0

Data Protection Search 19.4.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.