HIGH✓ PATCH🇬🇧 English

CVE-2023-39244

CVSS 7.3v3.1pub. 2024-02-15upd. 2025-01-23

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • Dell Enterprise Storage Integrator For Sap Landscape Management

    APP
    Dell
    < 10.0.0.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2023-39245CRITICAL9.8PL ✓ten sam produkt

Dell ESI for SAP LAMA – ujawnienie danych uwierzytelniających przez sieć (EHAC)

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓ten sam vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)

CVE-2026-67261CRITICAL9.8PL ✓ten sam vendor

Dell Virtual Storage Integrator – OS Command Injection z uprawnieniami root (RCE bez uwierzytelnienia)

CVE-2026-54489CRITICAL9.1PL ✓ten sam vendor

Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta

CVE-2026-46738CRITICAL9.1PL ✓ten sam vendor

Dell PowerProtect Data Manager – Improper Input Validation w REST API (privilege escalation)