Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Dell
Subscribe
|
Emc Powerconnect 7000
Subscribe
Emc Powerconnect 7000 Firmware
Subscribe
Emc Powerconnect 8024
Subscribe
Emc Powerconnect 8024 Firmware
Subscribe
Emc Powerconnect M6220
Subscribe
Emc Powerconnect M6220 Firmware
Subscribe
Emc Powerconnect M6348
Subscribe
Emc Powerconnect M6348 Firmware
Subscribe
Emc Powerconnect M8024
Subscribe
Emc Powerconnect M8024-k
Subscribe
Emc Powerconnect M8024-k Firmware
Subscribe
Emc Powerconnect M8024 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13388 | Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.dell.com/support/article/sln318359/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T20:48:15.827Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-3753
No data.
Status : Modified
Published: 2019-08-20T19:15:11.357
Modified: 2024-11-21T04:42:28.037
Link: CVE-2019-3753
No data.
OpenCVE Enrichment
No data.
EUVD