Description
Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46237 | Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft. |
References
History
Tue, 21 Jan 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell elastic Cloud Storage |
|
| CPEs | cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dell
Dell elastic Cloud Storage |
Fri, 27 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft. | |
| Weaknesses | CWE-294 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-12-27T14:54:52.568Z
Reserved: 2024-11-12T06:04:07.775Z
Link: CVE-2024-52534
Updated: 2024-12-27T14:54:46.874Z
Status : Analyzed
Published: 2024-12-25T16:15:21.997
Modified: 2025-01-21T21:30:49.030
Link: CVE-2024-52534
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD