CVE-2019-3736: Dell Emc Integrated Data Protection Appliance Firmware
High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other components using the privileges of the compromised user.
Affected products
- Dell Emc Integrated Data Protection Appliance Firmware: version 2.0 only; version 2.1 only; version 2.2 only
Published 2019-09-27. Last modified 2026-06-17.