HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-39244

CVSS 7.3v3.1pub. 2024-02-15upd. 2025-01-23

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • Dell Enterprise Storage Integrator For Sap Landscape Management

    APP
    Dell
    < 10.0.0.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-39245CRITICAL9.8PL ✓same product

Dell ESI for SAP LAMA – ujawnienie danych uwierzytelniających przez sieć (EHAC)

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓same vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)

CVE-2026-70419CRITICAL9.1same vendor

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements ...

CVE-2026-67261CRITICAL9.8PL ✓same vendor

Dell Virtual Storage Integrator – OS Command Injection z uprawnieniami root (RCE bez uwierzytelnienia)

CVE-2026-54489CRITICAL9.1PL ✓same vendor

Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta