Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
History

Fri, 27 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Description Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
Weaknesses CWE-294
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2024-12-25T16:04:17.253Z

Updated: 2024-12-27T14:54:52.568Z

Reserved: 2024-11-12T06:04:07.775Z

Link: CVE-2024-52534

cve-icon Vulnrichment

Updated: 2024-12-27T14:54:46.874Z

cve-icon NVD

Status : Received

Published: 2024-12-25T16:15:21.997

Modified: 2024-12-25T16:15:21.997

Link: CVE-2024-52534

cve-icon Redhat

No data.