7.8
CVE-2026-28261
- EPSS 0.02%
- Veröffentlicht 08.04.2026 12:43:54
- Zuletzt bearbeitet 13.04.2026 18:20:21
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to secret exposure. The attacker may be able to use the exposed secret to access the vulnerable system with privileges of the compromised account.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Elastic Cloud Storage Version < 4.2.0.1
Dell ≫ Objectscale Version < 4.1.0.3
Dell ≫ Objectscale Version4.2.0.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.036 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| security_alert@emc.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.