HIGH✓ PATCH🇬🇧 English

CVE-2023-39250

CVSS 7.8v3.1pub. 2023-08-16upd. 2024-11-21

Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Dell Replay Manager For VMware

    APP
    Dell
    < 3.1.2
  • Dell Storage Integration Tools For VMware

    APP
    Dell
    < 6.1.1
  • Dell Storage vSphere Client Plugin

    APP
    Dell
    < 6.1.1
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓ten sam vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)

CVE-2026-70419CRITICAL9.1ten sam vendor

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements ...

CVE-2026-54489CRITICAL9.1PL ✓ten sam vendor

Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta

CVE-2026-67261CRITICAL9.8PL ✓ten sam vendor

Dell Virtual Storage Integrator – OS Command Injection z uprawnieniami root (RCE bez uwierzytelnienia)

CVE-2026-40712CRITICAL9.1PL ✓ten sam vendor

Dell PowerProtect Data Manager – Improper Input Validation w REST API (Privilege Escalation)