CVE-2023-4129

MEDIUM

Dell Data Protection Central - Weak Encryption

Title source: rule
STIX 2.1

Description

Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover plaintext from a block of ciphertext.

Scores

CVSS v3 5.9
EPSS 0.0009
EPSS Percentile 26.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-326
Status published
Products (1)
dell/data_protection_central 19.9.0-10
Published Sep 27, 2023
Tracked Since Feb 18, 2026