CVE-2024-22433: Dell Data Protection Search
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of Confidentiality, Integrity, Protection, and remote takeover of the system. This is a high-severity vulnerability as it allows an attacker to take complete control of DP Search to affect downstream protected devices.
Affected products
- Dell Data Protection Search: from 19.2.0, before 19.6.4 (fixed in 19.6.4)
Published 2024-02-06. Last modified 2026-06-17.