CVE-2018-15773
MEDIUM
4,3
Source: [email protected]
Attack Vector: physical
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
MEDIUM
4,9
Source: [email protected]
Access Vector: local
Access Complexity: low
Authentication: none
Confidentiality: complete
Integrity: none
Availability: none
Description
AI Translation Available
Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0003
Percentile
0,1th
Updated
EPSS Score Trend (Last 91 Days)
200
Exposure of Sensitive Information to an Unauthorized Actor
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies:
Mobile, Not Technology-Specific, Web Based
Application
Data Protection \| Encryption by Dell
Version Range Affected
To
10.1.0
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:dell:data_protection_\|_encryption:*:*:*:*:enterprise:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.dell.com/support/article/us/en/04/sln314963/dell-encryption-enterpr…
https://www.dell.com/support/article/us/en/04/sln314963/dell-encryption-enterpr…