Artikelnummer: 000222470
Medium
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
---|---|---|---|
CVE-2024-22459 | Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to all buckets and their data within a namespace. | 6.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
---|---|---|---|
CVE-2024-22459 | Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to all buckets and their data within a namespace. | 6.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
CVEs Addressed | Product | Affected Version(s) | Remediated Versions | Link to Update |
---|---|---|---|---|
CVE-2024-22459 | Dell ECS | Versions 3.8 through 3.8.0.4 | ECS 3.8.0.5 |
https://www.dell.com/support/incidents-online |
CVE-2024-22459 | Dell ECS | Version 3.7 through 3.7.0.6 | ECS 3.7.0.7 |
https://www.dell.com/support/incidents-online |
CVE-2024-22459 | Dell ECS | Versions 3.6 through 3.6.2.5 | ECS 3.6.2.6 | https://www.dell.com/support/incidents-online |
CVEs Addressed | Product | Affected Version(s) | Remediated Versions | Link to Update |
---|---|---|---|---|
CVE-2024-22459 | Dell ECS | Versions 3.8 through 3.8.0.4 | ECS 3.8.0.5 |
https://www.dell.com/support/incidents-online |
CVE-2024-22459 | Dell ECS | Version 3.7 through 3.7.0.6 | ECS 3.7.0.7 |
https://www.dell.com/support/incidents-online |
CVE-2024-22459 | Dell ECS | Versions 3.6 through 3.6.2.5 | ECS 3.6.2.6 | https://www.dell.com/support/incidents-online |
None
Dell Technologies would like to thank Amund Tenstad for reporting this issue.
Revision | Date | Description |
1.0 | 2024-02-26 | Initial Release |
ECS, ECS Appliance Software with Encryption, ECS Appliance Software without Encryption
26 feb. 2024
Dell Security Advisory