DSA-2019-124: Dell EMC PowerConnect Security Vulnerability

Samenvatting: Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K firmware has been updated to address a vulnerability which may be potentially exploited to compromise the system.

Dit artikel is van toepassing op Dit artikel is niet van toepassing op Dit artikel is niet gebonden aan een specifiek product. Niet alle productversies worden in dit artikel vermeld.

Impact

High

Gegevens

Dell PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

CVSS Base Score:7.2 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Dell PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

CVSS Base Score:7.2 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Dell Technologies raadt aan dat alle klanten rekening houden met zowel de basisscore van CVSS als alle relevante tijdelijke en omgevingsscores die gevolgen kunnen hebben voor de mogelijke ernst van de specifieke beveiligingsproblemen.

Getroffen producten en herstel

Affected products:

The below Dell EMC PowerConnect models running firmware versions prior to 5.1.15.2: 

  • 8024
  • 7000
  • M6348
  • M6220
  • M8024
  • M8024-K

Remediation:

The following Dell EMC PowerConnect firmware release contains a resolution to the vulnerability:

  •     Dell EMC PowerConnect firmware version 5.1.15.2 and later.

Customers can download the latest firmware version at the support site for their respective model below:

  Dell EMC recommends all customers upgrade at the earliest opportunity. 
 

Affected products:

The below Dell EMC PowerConnect models running firmware versions prior to 5.1.15.2: 

  • 8024
  • 7000
  • M6348
  • M6220
  • M8024
  • M8024-K

Remediation:

The following Dell EMC PowerConnect firmware release contains a resolution to the vulnerability:

  •     Dell EMC PowerConnect firmware version 5.1.15.2 and later.

Customers can download the latest firmware version at the support site for their respective model below:

  Dell EMC recommends all customers upgrade at the earliest opportunity. 
 

Bevestigingen

Dell EMC would like to thank Daniel Cobb (@droctapus1) for reporting this vulnerability.

Verwante informatie

Getroffen producten

PowerConnect M6220, PowerConnect M6348, PowerConnect M8024, PowerConnect M8024-K
Artikeleigenschappen
Artikelnummer: 000125969
Artikeltype: Dell Security Advisory
Laatst aangepast: 05 jun. 2025
Vind antwoorden op uw vragen via andere Dell gebruikers
Support Services
Controleer of uw apparaat wordt gedekt door Support Services.