Fixed CVE-2019-3710

This commit is contained in:
DellEMCProductSecurity 2019-03-28 13:23:23 -04:00
parent e38ab5f12b
commit 121372ce5c

View File

@ -1,7 +1,7 @@
{ {
"CVE_data_meta": { "CVE_data_meta": {
"ASSIGNER": "secure@dell.com", "ASSIGNER": "secure@dell.com",
"DATE_PUBLIC": "2019-03-18T05:00:00.000Z", "DATE_PUBLIC": "2019-03-18T05:00:00.000Z"
"ID": "CVE-2019-3710", "ID": "CVE-2019-3710",
"STATE": "PUBLIC", "STATE": "PUBLIC",
"TITLE": "DSA-2019-034: Dell Networking OS10 Key Management Error Vulnerability" "TITLE": "DSA-2019-034: Dell Networking OS10 Key Management Error Vulnerability"
@ -17,7 +17,8 @@
"version": { "version": {
"version_data": [ "version_data": [
{ {
"version_value": "10.4.3.0" "version_affected": "<",
"version_value": "10.4.3"
} }
] ]
} }
@ -36,7 +37,7 @@
"description_data": [ "description_data": [
{ {
"lang": "eng", "lang": "eng",
"value": "Dell Networking OS10 has been updated to address a vulnerability which may be potentially exploited to compromise the system." "value": "Dell Networking OS10 versions prior to 10.4.3 contain a vulnerability caused by improper key management. As a result of this vulnerability, authentication and encryption can be bypassed, and an attacker can run arbitrary code with escalated user privileges."
} }
] ]
}, },
@ -65,7 +66,7 @@
"description": [ "description": [
{ {
"lang": "eng", "lang": "eng",
"value": "Dell Networking OS10 versions prior to 10.4.3 contain a vulnerability caused by improper key management. As a result of this vulnerability, authentication and encryption can be bypassed, and an attacker can run arbitrary code with escalated user privileges." "value": "As a result of this vulnerability, authentication and encryption can be bypassed, and an attacker can run arbitrary code with escalated user privileges."
} }
] ]
} }