Vulnerability Details CVE-2023-25934
DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify the body data of the request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.8%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2023-25934
-
cpe:2.3:a:dell:elastic_cloud_storage:-
-
cpe:2.3:a:dell:elastic_cloud_storage:3.0
-
cpe:2.3:a:dell:elastic_cloud_storage:3.6.0.0
-
cpe:2.3:a:dell:elastic_cloud_storage:3.6.0.1
-
cpe:2.3:a:dell:elastic_cloud_storage:3.6.1.0
-
cpe:2.3:a:dell:elastic_cloud_storage:3.6.1.1
-
cpe:2.3:a:dell:elastic_cloud_storage:3.6.1.2
-
cpe:2.3:a:dell:elastic_cloud_storage:3.6.2.2
-
cpe:2.3:a:dell:elastic_cloud_storage:3.6.2.3
-
cpe:2.3:a:dell:elastic_cloud_storage:3.6.2.4
-
cpe:2.3:a:dell:elastic_cloud_storage:3.6.2.5
-
cpe:2.3:a:dell:elastic_cloud_storage:3.6.2.6
-
cpe:2.3:a:dell:elastic_cloud_storage:3.7.0.0
-
cpe:2.3:a:dell:elastic_cloud_storage:3.7.0.1
-
cpe:2.3:a:dell:elastic_cloud_storage:3.7.0.2
-
cpe:2.3:a:dell:elastic_cloud_storage:3.7.0.3
-
cpe:2.3:a:dell:elastic_cloud_storage:3.7.0.4
-
cpe:2.3:a:dell:elastic_cloud_storage:3.7.0.5
-
cpe:2.3:a:dell:elastic_cloud_storage:3.7.0.6
-
cpe:2.3:a:dell:elastic_cloud_storage:3.7.0.7
-
cpe:2.3:a:dell:elastic_cloud_storage:3.8.0.0
-
cpe:2.3:a:dell:elastic_cloud_storage:3.8.0.1