Description
Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticated user with bucket or object-level access and the necessary privileges could potentially exploit this vulnerability to bypass retention policies and delete objects.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45787 | Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticated user with bucket or object-level access and the necessary privileges could potentially exploit this vulnerability to bypass retention policies and delete objects. |
References
History
Tue, 21 Jan 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell elastic Cloud Storage |
|
| CPEs | cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dell
Dell elastic Cloud Storage |
Thu, 26 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Dec 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticated user with bucket or object-level access and the necessary privileges could potentially exploit this vulnerability to bypass retention policies and delete objects. | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-12-26T18:07:42.679Z
Reserved: 2024-10-29T05:03:58.394Z
Link: CVE-2024-51540
Updated: 2024-12-26T18:07:38.856Z
Status : Analyzed
Published: 2024-12-26T16:15:29.640
Modified: 2025-01-21T21:30:52.310
Link: CVE-2024-51540
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD