Description
Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2026-09-28
Score: 5.6 Medium
EPSS: n/a
KEV: No
Impact: Information exposure via hard‑coded credentials
Action: Apply Update
AI Analysis

Impact

Dell Live Optics Collector releases prior to 27.2.13.310 embed a hard‑coded password, creating a Use of Hard‑coded Password weakness (CWE‑259). This flaw allows a local, low‑privileged attacker who gains access to the host to read or derive the internal credential that the collector uses. By obtaining this information the attacker can potentially disclose the collector configuration and any sensitive data transmitted to or received from the Dell Live Optics service.

Affected Systems

Affected deployments are those running Dell Live Optics Collector versions older than 27.2.13.310. In environments where the collector operates on-premises or in the cloud, any host that hosts these older images may be vulnerable because the hard‑coded credential is stored inside the collector binaries and configuration files.

Risk and Exploitability

The CVSS score of 5.6 indicates moderate severity, and the EPSS score is not provided, so exploitation probability cannot be quantified from the supplied data. Exploitation requires local, low‑privileged access, meaning an attacker must already have some foothold on the system where the collector runs. The vulnerability is not listed in CISA KEV, suggesting no publicly documented exploits exist yet. However, the hard‑coded password offers a clear north‑pole for information disclosure if local file or process access is achieved, potentially exposing privileged credentials and configuration details.

Generated by OpenCVE AI on September 28, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Live Optics Collector to version 27.2.13.310 or later.
  • Review collector configuration files and related binaries to ensure no hard‑coded passwords remain, and replace any found with secure, configurable credentials.
  • Restrict local access permissions for the collector service so that only necessary system accounts can run the process, reducing the opportunity for an attacker to obtain the embedded credential.

Generated by OpenCVE AI on September 28, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Hard‑coded Password Leading to Information Exposure in Dell Live Optics Collector

Mon, 28 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-259
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-28T14:27:19.520Z

Reserved: 2026-08-04T11:16:10.499Z

Link: CVE-2026-70413

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T15:17:23.350

Modified: 2026-09-28T15:17:23.350

Link: CVE-2026-70413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T15:30:02Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password