CVE-2024-22459
EUVD-2024-2000328.02.2024, 09:15
Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to all buckets and their data within a namespaceEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dell | elastic_cloud_storage | 3.6.0.0 ≤ 𝑥 < 3.6.2.6 |
| dell | elastic_cloud_storage | 3.7.0.0 ≤ 𝑥 < 3.7.0.7 |
| dell | elastic_cloud_storage | 3.8.0.0 ≤ 𝑥 < 3.8.0.5 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| dell | elastic_cloud_storage | 3.8 ≤ 𝑥 ≤ 3.8.0.4 | ADP |
| dell | elastic_cloud_storage | 3.7 ≤ 𝑥 ≤ 3.7.0.6 | ADP |
| dell | elastic_cloud_storage | 3.6 ≤ 𝑥 ≤ 3.6.2.5 | ADP |
Common Weakness Enumeration