Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure.
History

Tue, 17 Sep 2024 02:45:00 +0000


Tue, 17 Sep 2024 02:00:00 +0000


Fri, 13 Sep 2024 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell smartfabric Os10
Weaknesses CWE-798
CPEs cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell smartfabric Os10

Fri, 06 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Sep 2024 04:30:00 +0000

Type Values Removed Values Added
Description Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure.
Weaknesses CWE-259
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2024-09-06T04:18:27.225Z

Updated: 2024-09-17T01:50:13.135Z

Reserved: 2024-06-26T02:16:08.993Z

Link: CVE-2024-39585

cve-icon Vulnrichment

Updated: 2024-09-06T13:03:19.145Z

cve-icon NVD

Status : Modified

Published: 2024-09-06T05:15:13.590

Modified: 2024-09-17T02:15:49.397

Link: CVE-2024-39585

cve-icon Redhat

No data.