← Back to browse · API

CVE-2019-3746

Severity
CRITICAL
CVSS
9.8
EPSS
0.02121
Risk score
39.94
CISA KEV
No
PoC
No
Published
2019-09-27
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2019-13381, GHSA-3Q4Q-6VXP-X66F
Products
Dell:Integrated Data Protection Appliance prior to 2.3
Sources
euvd EUVD-2019-13381

Description

Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticated remote user may exploit this vulnerability to launch a brute-force authentication attack in order to gain access to the system.

References