← back
CVE-2024-37137

CVE-2024-37137

CVSS 3.8 LOWEPSS 0.1%CWE-1240
In short

Dell Key Trust Platform versions 3.0.6 and earlier use weak cryptographic methods that could allow a local attacker with administrator access to read sensitive information they shouldn't access.

Technical detail

Dell Key Trust Platform v3.0.6 and prior implements cryptographic primitives insecurely (CWE-1240), allowing a local privileged attacker to bypass intended access controls and disclose sensitive data. Attack requires local system access and elevated privileges; impact is limited to information disclosure.

Summary generated and translated by AI from the official description.
Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to privileged information disclosure.
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L
Affected products
Dell · CloudLink

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →