# CVE-2019-3736

## Summary

- **CVE ID:** CVE-2019-3736
- **Severity:** HIGH
- **CVSS Score:** 8.2 (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-257
- **Published:** Sep 27, 2019
- **Last Modified:** Mar 14, 2026

## Description

Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other components using the privileges of the compromised user.

## Affected Products

- Dell — Integrated Data Protection Appliance (prior to 2.3)

## References

- [CNA](https://www.dell.com/support/security/en-us/details/536363/DSA-2019-112-Dell-EMC-Integrated-Data-Protection-Appliance-Multiple-Vulnerabilities)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.07%
- **EPSS Percentile:** 22.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._