Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to all buckets and their data within a namespace
2024-02-28T09:15:43.877
2025-02-04T17:26:52.583
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dell | elastic_cloud_storage | < 3.6.2.6 | Yes |
Application | dell | elastic_cloud_storage | < 3.7.0.7 | Yes |
Application | dell | elastic_cloud_storage | < 3.8.0.5 | Yes |