DSA-2019-124: Dell EMC PowerConnect Security Vulnerability

Riepilogo: Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K firmware has been updated to address a vulnerability which may be potentially exploited to compromise the system.

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Impatto

High

Dettagli

Dell PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

CVSS Base Score:7.2 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Dell PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

CVSS Base Score:7.2 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Dell Technologies raccomanda a tutti i clienti di prendere in considerazione sia il punteggio base CVSS, sia ogni eventuale punteggio temporale o ambientale che possa avere effetti sul livello di gravità potenziale associato a una specifica vulnerabilità di sicurezza.

Prodotti interessati e correzione

Affected products:

The below Dell EMC PowerConnect models running firmware versions prior to 5.1.15.2: 

  • 8024
  • 7000
  • M6348
  • M6220
  • M8024
  • M8024-K

Remediation:

The following Dell EMC PowerConnect firmware release contains a resolution to the vulnerability:

  •     Dell EMC PowerConnect firmware version 5.1.15.2 and later.

Customers can download the latest firmware version at the support site for their respective model below:

  Dell EMC recommends all customers upgrade at the earliest opportunity. 
 

Affected products:

The below Dell EMC PowerConnect models running firmware versions prior to 5.1.15.2: 

  • 8024
  • 7000
  • M6348
  • M6220
  • M8024
  • M8024-K

Remediation:

The following Dell EMC PowerConnect firmware release contains a resolution to the vulnerability:

  •     Dell EMC PowerConnect firmware version 5.1.15.2 and later.

Customers can download the latest firmware version at the support site for their respective model below:

  Dell EMC recommends all customers upgrade at the earliest opportunity. 
 

Ringraziamenti

Dell EMC would like to thank Daniel Cobb (@droctapus1) for reporting this vulnerability.

Informazioni correlate

Prodotti interessati

PowerConnect M6220, PowerConnect M6348, PowerConnect M8024, PowerConnect M8024-K
Proprietà dell'articolo
Numero articolo: 000125969
Tipo di articolo: Dell Security Advisory
Ultima modifica: 05 giu 2025
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.