CVE-2024-37137
CVE-2024-37137
In short
Dell Key Trust Platform versions 3.0.6 and earlier use weak cryptographic methods that could allow a local attacker with administrator access to read sensitive information they shouldn't access.
Technical detail
Dell Key Trust Platform v3.0.6 and prior implements cryptographic primitives insecurely (CWE-1240), allowing a local privileged attacker to bypass intended access controls and disclose sensitive data. Attack requires local system access and elevated privileges; impact is limited to information disclosure.
Summary generated and translated by AI from the official description.
Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to privileged information disclosure.
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L
Affected products
Dell · CloudLinkWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →