CVE-2023-39250

Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:replay_manager_for_vmware:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_integration_tools_for_vmware:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_vsphere_client_plugin:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:14

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities - Vendor Advisory
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 7.8

03 Nov 2023, 19:00

Type Values Removed Values Added
CPE cpe:2.3:a:dell:storage_integration_tools_for_vmware:06.01.00.016:*:*:*:*:*:*:* cpe:2.3:a:dell:replay_manager_for_vmware:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_vsphere_client_plugin:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_integration_tools_for_vmware:*:*:*:*:*:*:*:*
First Time Dell replay Manager For Vmware
Dell storage Vsphere Client Plugin

11 Oct 2023, 06:15

Type Values Removed Values Added
Summary Dell Storage Integration Tools for VMware (DSITV) 06.01.00.016 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks. Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.
CWE CWE-668 CWE-540

24 Aug 2023, 16:17

Type Values Removed Values Added
First Time Dell storage Integration Tools For Vmware
Dell
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:dell:storage_integration_tools_for_vmware:06.01.00.016:*:*:*:*:*:*:*
CWE CWE-540 CWE-668
References (MISC) https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities - (MISC) https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities - Vendor Advisory

16 Aug 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-16 16:15

Updated : 2024-11-21 08:14


NVD link : CVE-2023-39250

Mitre link : CVE-2023-39250

CVE.ORG link : CVE-2023-39250


JSON object : View

Products Affected

dell

  • storage_integration_tools_for_vmware
  • storage_vsphere_client_plugin
  • replay_manager_for_vmware
CWE
CWE-540

Inclusion of Sensitive Information in Source Code

CWE-668

Exposure of Resource to Wrong Sphere