Home
HIGH: 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HDefault status
unaffected
Any version before 3.8.1.3
affected
Description
Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticated user with bucket or object-level access and the necessary privileges could potentially exploit this vulnerability to bypass retention policies and delete objects.
Problem types
CWE-190: Integer Overflow or Wraparound
Product status
Any version before 3.8.1.3
References
www.dell.com/...update-for-dell-ecs-multiple-vulnerabilities