CVE-2023-28045 MEDIUM

CVE-2023-28045

Vendor Dell
Product CloudIQ Collector
Weakness CWE-311 · Missing encryption
Published May 19, 2023
Last update February 12, 2025

CVSS base score

6.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability, leading to gain access to unauthorized data.

Key dates

02Disclosure timeline

May 19, 2023 CVE published
February 12, 2025 Record updated