Impact
This vulnerability is a CWE‑200 Sensitive Information Disclosure in Dell Virtual Storage Integrator for VMware vSphere Client. An unauthenticated remote attacker could gain access to active session credentials, permitting the attacker to fully impersonate authenticated users, including administrators. The potential impact is a loss of confidentiality, integrity, and availability across the virtual storage environment, with the ability to conduct arbitrary administrative actions.
Affected Systems
The affected product is Dell Virtual Storage Integrator for VMware vSphere Client from Dell. Versions prior to 10.11.1.0 are impacted. No other vendor or product is listed.
Risk and Exploitability
The CVSS score is 9.1, indicating a critical severity. The EPSS score is not available, but the vulnerability was deemed critical enough that Dell recommends immediate upgrade. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an unauthenticated attacker can exploit this remotely, likely over the vSphere Client network interface, to obtain session credentials.
OpenCVE Enrichment