PT-2024-5195 · Dell · Dell Ecs

CVE-2024-30473

·

Published

2024-03-27

·

Updated

2024-07-19

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Dell ECS versions prior to 3.8.1
Description: The issue is related to insufficient access control in the Dell EMC Elastic Cloud Storage (ECS) platform, which can be exploited by a remote attacker to elevate their privileges. A high-privileged attacker could potentially exploit this vulnerability, gaining access to unauthorized endpoints.
Recommendations: For versions prior to 3.8.1, update to version 3.8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to user management functions to minimize the risk of exploitation.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05752
CVE-2024-30473

Affected Products

Dell Ecs