Impact
Dell Live Optics Collector releases prior to 27.2.13.310 embed a hard‑coded password, creating a Use of Hard‑coded Password weakness (CWE‑259). This flaw allows a local, low‑privileged attacker who gains access to the host to read or derive the internal credential that the collector uses. By obtaining this information the attacker can potentially disclose the collector configuration and any sensitive data transmitted to or received from the Dell Live Optics service.
Affected Systems
Affected deployments are those running Dell Live Optics Collector versions older than 27.2.13.310. In environments where the collector operates on-premises or in the cloud, any host that hosts these older images may be vulnerable because the hard‑coded credential is stored inside the collector binaries and configuration files.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity, and the EPSS score is not provided, so exploitation probability cannot be quantified from the supplied data. Exploitation requires local, low‑privileged access, meaning an attacker must already have some foothold on the system where the collector runs. The vulnerability is not listed in CISA KEV, suggesting no publicly documented exploits exist yet. However, the hard‑coded password offers a clear north‑pole for information disclosure if local file or process access is achieved, potentially exposing privileged credentials and configuration details.
OpenCVE Enrichment