CVE-2024-22433
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 6, 2024
Updated: Feb 13, 2024
CWE ID 538
Summary
CVE-2024-22433 is a high-severity vulnerability affecting Dell Data Protection Search 19.2.0 and later versions. The issue involves an exposed password in plain text during the usage of LdapSettings.get_ldap_info in DP Search. A remote, unauthorized, and unauthenticated attacker could exploit this vulnerability, leading to loss of Confidentiality, Integrity, Protection, and potentially takeover of the system. The attacker could gain complete control over DP Search, impacting downstream protected devices.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Dell Technologies, Inc.