CVE Vulnerabilities

CVE-2023-39250

Inclusion of Sensitive Information in Source Code

Published: Aug 16, 2023 | Modified: Nov 03, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.

Weakness

Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

Affected Software

Name Vendor Start Version End Version
Replay_manager_for_vmware Dell * 3.1.2 (excluding)
Storage_integration_tools_for_vmware Dell * 6.1.1 (excluding)
Storage_vsphere_client_plugin Dell * 6.1.1 (excluding)

Potential Mitigations

References