Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDell Replay Manager For VMware
APPDell< 3.1.2Dell Storage Integration Tools For VMware
APPDell< 6.1.1Dell Storage vSphere Client Plugin
APPDell< 6.1.1
Related vulnerabilities
Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)
Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta
Dell Virtual Storage Integrator – OS Command Injection z uprawnieniami root (RCE bez uwierzytelnienia)
Dell PowerProtect Data Manager – Improper Input Validation w REST API (Privilege Escalation)
Dell PowerProtect Data Manager – Improper Input Validation w REST API (privilege escalation)