CVE-2019-3746
Summary
| CVE | CVE-2019-3746 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-27 21:15:00 UTC |
| Updated | 2019-10-09 23:49:00 UTC |
| Description | Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticated remote user may exploit this vulnerability to launch a brute-force authentication attack in order to gain access to the system. |
Risk And Classification
Problem Types: CWE-307
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dell | Emc Idpa Dp4400 | - | All | All | All |
| Hardware | Dell | Emc Idpa Dp4400 | - | All | All | All |
| Hardware | Dell | Emc Idpa Dp5800 | - | All | All | All |
| Hardware | Dell | Emc Idpa Dp5800 | - | All | All | All |
| Hardware | Dell | Emc Idpa Dp8300 | - | All | All | All |
| Hardware | Dell | Emc Idpa Dp8300 | - | All | All | All |
| Hardware | Dell | Emc Idpa Dp8800 | - | All | All | All |
| Hardware | Dell | Emc Idpa Dp8800 | - | All | All | All |
| Operating System | Dell | Emc Integrated Data Protection Appliance Firmware | 2.0 | All | All | All |
| Operating System | Dell | Emc Integrated Data Protection Appliance Firmware | 2.1 | All | All | All |
| Operating System | Dell | Emc Integrated Data Protection Appliance Firmware | 2.2 | All | All | All |
| Operating System | Dell | Emc Integrated Data Protection Appliance Firmware | 2.0 | All | All | All |
| Operating System | Dell | Emc Integrated Data Protection Appliance Firmware | 2.1 | All | All | All |
| Operating System | Dell | Emc Integrated Data Protection Appliance Firmware | 2.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory | Dell US | CONFIRM | www.dell.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.