Lucene search

K
nvd[email protected]NVD:CVE-2022-34442
HistoryJan 18, 2023 - 7:15 a.m.

CVE-2022-34442

2023-01-1807:15:09
CWE-798
CWE-321
web.nvd.nist.gov
2
dell emc
scg policy manager
hard-coded cryptographic key
ldap user privileges

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.002

Percentile

58.4%

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. Β An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges.

Affected configurations

Nvd
Node
dellemc_secure_connect_gateway_policy_managerRange5.10.00.00–5.14.00.00
VendorProductVersionCPE
dellemc_secure_connect_gateway_policy_manager*cpe:2.3:a:dell:emc_secure_connect_gateway_policy_manager:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.002

Percentile

58.4%

Related for NVD:CVE-2022-34442