CVE-2018-15765
Summary
| CVE | CVE-2018-15765 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-18 22:29:00 UTC |
| Updated | 2019-10-09 23:35:00 UTC |
| Description | Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens which may prove useful to an attacker for crafting malicious authentication tokens for querying the application and subsequent attacks. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dell | Emc Secure Remote Services | All | All | All | All |
| Application | Dell | Emc Secure Remote Services | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Dell EMC Secure Remote Services File Permission Bugs Let Local Users Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Dell EMC ESRS Virtual Edition Multiple Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Full Disclosure: DSA-2018-157: Dell EMC ESRS Virtual Edition Multiple Vulnerabilities | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.