CVE-2023-39250

Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:replay_manager_for_vmware:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_integration_tools_for_vmware:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_vsphere_client_plugin:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:14

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities - Vendor Advisory
Summary
  • (es) Las versiones Dell Storage Integration Tools para VMware (DSITV) y Dell Storage vSphere Client Plugin (DSVCP) anteriores a la 6.1.1 y Replay Manager para las versiones VMware (RMSV) anteriores a la 3.1.2 contienen una vulnerabilidad de divulgación de información. Un usuario malintencionado local con pocos privilegios podría explotar esta vulnerabilidad para recuperar una clave de cifrado que podría ayudar en futuros ataques.
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 7.8

Information

Published : 2023-08-16 16:15

Updated : 2024-11-21 08:14


NVD link : CVE-2023-39250

Mitre link : CVE-2023-39250

CVE.ORG link : CVE-2023-39250


JSON object : View

Products Affected

dell

  • replay_manager_for_vmware
  • storage_vsphere_client_plugin
  • storage_integration_tools_for_vmware
CWE
CWE-540

Inclusion of Sensitive Information in Source Code

CWE-668

Exposure of Resource to Wrong Sphere