CVE-2024-22459

Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to all buckets and their data within a namespace
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*

History

04 Feb 2025, 17:26

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000222470/dsa-2024-078-security-update-for-dell-ecs-access-control-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000222470/dsa-2024-078-security-update-for-dell-ecs-access-control-vulnerability - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Dell
Dell elastic Cloud Storage
CPE cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*

Information

Published : 2024-02-28 09:15

Updated : 2025-02-04 17:26


NVD link : CVE-2024-22459

Mitre link : CVE-2024-22459

CVE.ORG link : CVE-2024-22459


JSON object : View

Products Affected

dell

  • elastic_cloud_storage
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo