← Vulnerability feed

Vulnerability record · CVE-2019-3736 · published 27 September 2019

CVE-2019-3736: Dell emc integrated data protection appliance firmware broken cryptographic algorithm vulnerability

Dell · Emc Integrated Data Protection Appliance Firmware

Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other components using the privileges of the compromised user.

7.2 CVSS 3.1 High EPSS 0.70% · top 48.7% CWE-257 · CWE-257CWE-327 · Broken cryptographic algorithm
7.2CVSS 3.1 base score, v2 4.0
0.70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other components using the privileges of the compromised user.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-3736 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-5341Dell emc avamar server deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data…EPSS 4.3%8.8CVE-2019-3746Dell emc integrated data protection appliance firmware improper restriction of authentication attempts vulnerabilityDell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticat…EPSS 2.1%7.2CVE-2019-18581Dell emc data protection advisor missing authorization vulnerabilityDell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missin…EPSS 3.9%7.2CVE-2019-18582Dell emc data protection advisor code injection vulnerabilityDell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side t…EPSS 4.6%4.8CVE-2019-3747Dell emc integrated data protection appliance firmware cross-site scripting vulnerabilityDell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability. A remote malicious ACM admin…EPSS 0.78%7.5CVE-2026-20128Cisco Catalyst SD-WAN Manager DCA credential file exposureCisco Catalyst SD-WAN Manager stores the Data Collection Agent (DCA) user password in a recoverable credential file on the affected system. An unauth…KEVEPSS 7.1%analysed

Source: NIST National Vulnerability Database (record CVE-2019-3736), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.