Home
MEDIUM: 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:LDefault status
unaffected
Any version before 4.3.0.0 or later
affected
Default status
unaffected
Any version before 4.3.0.0 or later
affected
Description
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in transit.
Problem types
CWE-302: Authentication Bypass by Assumed-Immutable Data
Product status
Any version before 4.3.0.0 or later
Any version before 4.3.0.0 or later
References
www.dell.com/...s-and-objectscale-multiple-vulnerabilities-1