Dell ECS
cpe:2.3:a:dellemc:elastic_cloud_storage:*:*:*:*:*:*:*
- < 3.8.1.5
A vulnerability exists in Dell ECS versions prior to 3.8.1.5 and ObjectScale version 4.0.0.0, allowing an unauthenticated attacker with local access to exploit hard-coded cryptographic keys. This could lead to unauthorized access. The vulnerability affects only those ECS versions upgraded to 3.8.1.5 or ObjectScale versions upgraded to 4.0.0.0.
Exploitation could result in unauthorized access to the affected system.
Users should upgrade to ECS version 3.8.1.5 or ObjectScale version 4.0.0.0, then rotate the SSH keys as documented in Dell Knowledge Base article 000339248.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.