Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and Dell Data Lakehouse versions prior to 1.2.0.0 contain an Insecure Storage of Sensitive Information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. The attacker may be able to use information disclosed to gain unauthorized access to pods within the cluster.
History

Thu, 22 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell data Lakehouse
Dell insightiq
Dell powerflex Appliance Intelligent Catalog
Dell powerflex Manager
Dell powerflex Rack Release Certification Matrix
CPEs cpe:2.3:a:dell:data_lakehouse:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:insightiq:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerflex_appliance_intelligent_catalog:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerflex_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerflex_rack_release_certification_matrix:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell data Lakehouse
Dell insightiq
Dell powerflex Appliance Intelligent Catalog
Dell powerflex Manager
Dell powerflex Rack Release Certification Matrix

Tue, 10 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Dec 2024 02:30:00 +0000

Type Values Removed Values Added
Description Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and Dell Data Lakehouse versions prior to 1.2.0.0 contain an Insecure Storage of Sensitive Information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. The attacker may be able to use information disclosed to gain unauthorized access to pods within the cluster.
Weaknesses CWE-922
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-12-10T21:27:23.301Z

Reserved: 2024-06-03T12:10:32.206Z

Link: CVE-2024-37144

cve-icon Vulnrichment

Updated: 2024-12-10T21:27:18.933Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-10T03:15:05.730

Modified: 2026-01-22T16:16:45.403

Link: CVE-2024-37144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.