VulnerabilityModified
CVE-2018-15765
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability.
MEDIUM 5.5EPSS 0.44%
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens which may prove useful to an attacker for crafting malicious authentication tokens for querying the application and subsequent attacks.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- dell/emc secure remote services
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/105694Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041877Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2018/Oct/35Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105694Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041877Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2018/Oct/35Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.