CVE-2019-3762Improper Following of a Certificate's Chain of Trust in Dell Data Protection Central

Severity
7.5HIGHNVD
EPSS
0.2%
top 53.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMay 24

Description

Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certificate from Data Protection Central to impersonate a valid system to compromise the integrity of data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5dell/data_protection_central1.0, 1.0.1, 18.1, 18.2, 19.1

🔴Vulnerability Details

2
GHSA
GHSA-5r88-pc2r-4575: Data Protection Central versions 12022-05-24
CVEList
CVE-2019-3762: Data Protection Central versions 12020-03-18
CVE-2019-3762 — Dell vulnerability | cvebase