ID

VAR-201910-0270


CVE

CVE-2019-3767


TITLE

Dell ImageAssist Vulnerable to information disclosure

Trust: 0.8

sources: JVNDB: JVNDB-2019-010748

DESCRIPTION

Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some sensitive encrypted information in the images it creates. A privileged user of a system running an operating system that was deployed with Dell ImageAssist could potentially retrieve this sensitive information to then compromise the system and related systems. Dell ImageAssist is a tool used by Dell to capture user's Windows installation configuration. This vulnerability stems from configuration errors in network systems or products during operation. An unauthorized attacker could exploit the vulnerability to obtain sensitive information of the affected components

Trust: 1.71

sources: NVD: CVE-2019-3767 // JVNDB: JVNDB-2019-010748 // VULHUB: VHN-155202

AFFECTED PRODUCTS

vendor:dellmodel:imageassistscope:ltversion:8.7.15

Trust: 1.8

sources: JVNDB: JVNDB-2019-010748 // NVD: CVE-2019-3767

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-3767
value: HIGH

Trust: 1.0

security_alert@emc.com: CVE-2019-3767
value: HIGH

Trust: 1.0

NVD: CVE-2019-3767
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201910-815
value: HIGH

Trust: 0.6

VULHUB: VHN-155202
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2019-3767
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-155202
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-3767
baseSeverity: HIGH
baseScore: 8.2
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.5
impactScore: 6.0
version: 3.1

Trust: 1.0

security_alert@emc.com: CVE-2019-3767
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 6.0
version: 3.0

Trust: 1.0

NVD: CVE-2019-3767
baseSeverity: MEDIUM
baseScore: 4.4
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-155202 // JVNDB: JVNDB-2019-010748 // CNNVD: CNNVD-201910-815 // NVD: CVE-2019-3767 // NVD: CVE-2019-3767

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

problemtype:CWE-312

Trust: 1.1

sources: VULHUB: VHN-155202 // JVNDB: JVNDB-2019-010748 // NVD: CVE-2019-3767

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201910-815

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201910-815

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-010748

PATCH

title:DSA-2019-139url:https://www.dell.com/support/article/us/en/19/sln318831/dsa-2019-139

Trust: 0.8

title:Dell ImageAssist Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=100350

Trust: 0.6

sources: JVNDB: JVNDB-2019-010748 // CNNVD: CNNVD-201910-815

EXTERNAL IDS

db:NVDid:CVE-2019-3767

Trust: 2.5

db:JVNDBid:JVNDB-2019-010748

Trust: 0.8

db:CNNVDid:CNNVD-201910-815

Trust: 0.7

db:VULHUBid:VHN-155202

Trust: 0.1

sources: VULHUB: VHN-155202 // JVNDB: JVNDB-2019-010748 // CNNVD: CNNVD-201910-815 // NVD: CVE-2019-3767

REFERENCES

url:https://www.dell.com/support/article/us/en/19/sln318831/dsa-2019-139

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-3767

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-3767

Trust: 0.8

sources: VULHUB: VHN-155202 // JVNDB: JVNDB-2019-010748 // CNNVD: CNNVD-201910-815 // NVD: CVE-2019-3767

SOURCES

db:VULHUBid:VHN-155202
db:JVNDBid:JVNDB-2019-010748
db:CNNVDid:CNNVD-201910-815
db:NVDid:CVE-2019-3767

LAST UPDATE DATE

2024-11-23T22:44:49.496000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-155202date:2020-10-16T00:00:00
db:JVNDBid:JVNDB-2019-010748date:2019-10-23T00:00:00
db:CNNVDid:CNNVD-201910-815date:2020-10-19T00:00:00
db:NVDid:CVE-2019-3767date:2024-11-21T04:42:29.523

SOURCES RELEASE DATE

db:VULHUBid:VHN-155202date:2019-10-14T00:00:00
db:JVNDBid:JVNDB-2019-010748date:2019-10-23T00:00:00
db:CNNVDid:CNNVD-201910-815date:2019-10-14T00:00:00
db:NVDid:CVE-2019-3767date:2019-10-14T18:15:10.670