Home
MEDIUM: 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
Any version before 3.5.1.7
affected
Any version before 3.6.2.4
affected
Description
Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data.
Problem types
CWE-284: Improper Access Control
Product status
Any version before 3.5.1.7
Any version before 3.6.2.4
References
dellservices.lightning.force.com/.../ka06P0000004RFTQA2/view