Cryptographic issues in EMC Integrated Data Protection Appliance - CVE-2019-3736

 

Cryptographic issues in EMC Integrated Data Protection Appliance - CVE-2019-3736

Published: September 30, 2019


Vulnerability identifier: #VU21443
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3736
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to weak cryptography in the ACM component. A remote authenticated attacker with root privileges can use a support tool to decrypt encrypted passwords stored locally on the system and use it to access other components using the privileges of the compromised user.

Affected software

EMC Integrated Data Protection Appliance

How to mitigate CVE-2019-3736

Install updates from vendor's website.

EMC Integrated Data Protection Appliance - update to 2.3

External References

Related Security Bulletins