Dell Encryption Enterprise Information Disclosure Vulnerability

요약: Information Disclosure Vulnerability in Dell Encryption Enterprise (formerly Dell Data Protection | Encryption).

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

증상

CVE Identifier: CVE-2018-15773

Severity: Medium


Affected Products:

  • Dell Encryption Enterprise
  • Dell Data Protection | Encryption

Affected Versions:

  • v10.0.0 and Earlier

Dell Encryption (formerly Dell Data Protection | Encryption) v10.0.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive computer files.

원인

Not Applicable

해결

The following Dell Encryption Enterprise release contains a resolution to this vulnerability:

  • Dell Encryption v10.1.0 and later

Dell Technologies recommends all customers upgrade at the earliest opportunity.

Link to remedies:

Customers can download the latest Dell Encryption software from:

https://www.dell.com/support/home/product-support/product/dell-data-protection-encryption/drivers

Dell Endpoint Security Suite Enterprise software is made available to customers on their ddpe.credant.com account, or it can be obtained through Dell ProSupport.

Credit:

Dell would like to thank Jan van der Put and Harm Blankers of REQON Security for reporting this vulnerability.

Dell Technologies recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information provided as is without warranty of any kind. Dell disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title, and noninfringement. In no event shall Dell or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Dell or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.


To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

해당 제품

Dell Encryption
문서 속성
문서 번호: 000130673
문서 유형: Solution
마지막 수정 시간: 16 1월 2024
버전:  10
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.