# CVE-2024-22433

## Summary

- **CVE ID:** CVE-2024-22433
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L)
- **CWE:** CWE-538
- **Published:** Feb 1, 2024
- **Last Modified:** Mar 13, 2026

## Description

Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of Confidentiality, Integrity, Protection, and remote takeover of the system. This is a high-severity vulnerability as it allows an attacker to take complete control of DP Search to affect downstream protected devices.

## Affected Products

- Dell — Data Protection Search (19.2.0)
- Dell — Data Protection Search (19.3.0)
- Dell — Data Protection Search (19.4.0)
- Dell — Data Protection Search (19.5.0)
- Dell — Data Protection Search (19.5.1)
- Dell — Data Protection Search (19.6.0)
- Dell — Data Protection Search (19.6.1)
- Dell — Data Protection Search (19.6.2)
- Dell — Data Protection Search (19.6.3)

## References

- [CNA](https://www.dell.com/support/kbdoc/en-us/000221720/dsa-2024-063-security-update-for-dell-data-protection-search-multiple-security-vulnerabilities)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.64%
- **EPSS Percentile:** 48.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._