PT-2019-16688 · Dell Emc · Dell Emc Integrated Data Protection Appliance

Published

2019-09-27

·

Updated

2019-10-09

·

CVE-2019-3746

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC Integrated Data Protection Appliance versions prior to 2.3
Description The issue allows an authenticated remote user to launch a brute-force authentication attack against the ACM API, potentially gaining access to the system, due to the lack of limitation on the number of authentication attempts.
Recommendations For versions prior to 2.3, update to version 2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the ACM API to minimize the risk of exploitation.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3746

Affected Products

Dell Emc Integrated Data Protection Appliance