PT-2019-16688 · Dell Emc · Dell Emc Integrated Data Protection Appliance

Publicado

2019-09-27

·

Atualizado

2019-10-09

·

CVE-2019-3746

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC Integrated Data Protection Appliance versions prior to 2.3
Description The issue allows an authenticated remote user to launch a brute-force authentication attack against the ACM API, potentially gaining access to the system, due to the lack of limitation on the number of authentication attempts.
Recommendations For versions prior to 2.3, update to version 2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the ACM API to minimize the risk of exploitation.

Correção

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-3746

Produtos afetados

Dell Emc Integrated Data Protection Appliance