Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens which may prove useful to an attacker for crafting malicious authentication tokens for querying the application and subsequent attacks.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://seclists.org/fulldisclosure/2018/Oct/35 | third party advisory mailing list |
http://www.securityfocus.com/bid/105694 | third party advisory vdb entry |
http://www.securitytracker.com/id/1041877 | third party advisory vdb entry |