Impact
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions before 4.4.0.0 contain a use of a broken or risky cryptographic algorithm. A high‑privileged local attacker can exploit this flaw, potentially leading to the disclosure of sensitive data. The weakness involves improper algorithm selection, which may allow decryption or other cryptographic failures.
Affected Systems
The affected products are Dell Elastic Cloud Storage (ECS) versions 3.8.1.0 to 3.8.1.7 and Dell ObjectScale versions earlier than 4.4.0.0. These systems handle object storage and may expose business‑critical data if compromised.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, and the EPSS score of <1% denotes a very low probability of exploitation in the wild at this time. Because the vulnerability requires high privileged local access, the attack surface is limited to administrators or trusted users with elevated permissions. The vulnerability is not listed in the CISA KEV catalog, so there is no current evidence of widespread exploitation, but applying the patch remains prudent.
OpenCVE Enrichment