PT-2018-13192 · Dell · Dell Encryption+2

Published

2018-10-11

·

Updated

2020-08-24

·

CVE-2018-15766

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dell Encryption versions prior to 10.0.1 Dell Endpoint Security Suite Enterprise versions prior to 2.0.1
Description The issue allows users to bypass existing password length policies, potentially creating insecure passwords. This occurs when the "Minimum Password Length" group policy object is overwritten and set to a value of 1 during the installation of the "Encryption Management Agent" or "EMAgent" application.
Recommendations For Dell Encryption versions prior to 10.0.1, update to version 10.0.1 or later to resolve the issue. For Dell Endpoint Security Suite Enterprise versions prior to 2.0.1, update to version 2.0.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15766

Affected Products

Dell Encryption
Dell Endpoint Security Suite Enterprise
Encryption Management Agent