CVE-2024-28974

EUVD-2024-26036
Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.6 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
delldata_protection_advisor
19.5 ≤
𝑥
< 19.9
delldp4400_firmware
𝑥
≤ 2.7.6
delldp5900_firmware
𝑥
≤ 2.7.6
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
dellemc_powerprotect_data_protection_appliance
𝑥
≤ 2.7.6
ADP
dellemc_data_protection_advisor
19.5 ≤
𝑥
≤ 19.9
ADP