CVE-2023-39250
16.08.2023, 16:15
Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.Enginsight
Vendor | Product | Version |
---|---|---|
dell | replay_manager_for_vmware | 𝑥 < 3.1.2 |
dell | storage_integration_tools_for_vmware | 𝑥 < 6.1.1 |
dell | storage_vsphere_client_plugin | 𝑥 < 6.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-540 - Inclusion of Sensitive Information in Source CodeSource code on a web server or repository often contains sensitive information and should generally not be accessible to users.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
References