Dell EMC AppSync Vulnerability Exposes Sensitive Information
CVE-2024-22464

6.2MEDIUM

Key Information:

Vendor

Dell

Status
Vendor
CVE Published:
8 February 2024

What is CVE-2024-22464?

Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in AppSync server logs. A high privileged remote attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable system with privileges of the compromised account.

Affected Version(s)

AppSync 4.2.0.0 <= 4.6.0.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.