Home
MEDIUM: 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
Any version before 4.2.0.0
affected
Description
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sensitive Information in Source Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Problem types
CWE-540: Inclusion of Sensitive Information in Source Code
Product status
Any version before 4.2.0.0
References
www.dell.com/...ecs-and-objectscale-multiple-vulnerabilities