Cryptographic issues in EMC Integrated Data Protection Appliance - CVE-2019-3736
Published: September 30, 2019
Vulnerability identifier: #VU21443
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3736
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to weak cryptography in the ACM component. A remote authenticated attacker with root privileges can use a support tool to decrypt encrypted passwords stored locally on the system and use it to access other components using the privileges of the compromised user.
Affected software
EMC Integrated Data Protection Appliance
How to mitigate CVE-2019-3736
Install updates from vendor's website.
EMC Integrated Data Protection Appliance - update to 2.3