CVE-2019-3736
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other components using the privileges of the compromised user.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.07%
- CWE
- CWE-257
- Published
- 2019-09-27
- Last modified
- 2026-03-14
Affected products
- Dell Integrated Data Protection Appliance
Weakness type
Related vulnerabilities
- CVE-2026-20128 — Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
- CVE-2025-8904 — Privilege escalation issue in Amazon EMR Secret Agent component
- CVE-2025-6996 — Improper Encryption in Ivanti Endpoint Manager
- CVE-2025-6995 — Improper Encryption in Ivanti Endpoint Manager
- CVE-2026-30785 — RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
- CVE-2022-34838 — ABB Ability TM Operations Data Management Zenon Zenon Log Server file access control
- CVE-2022-32519 — A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE
- CVE-2023-31150 — Storing Passwords in a Recoverable Format