DSA-2026-231: Security Update for Dell AIOps Collector for Default Credential Vulnerability

Zusammenfassung: Dell AIOps Collector remediation is available for use of default credentials that could be exploited by malicious users to compromise the affected system.

Dieser Artikel gilt für Dieser Artikel gilt nicht für Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden. In diesem Artikel werden nicht alle Produktversionen aufgeführt.

Auswirkungen

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32652 Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged attacker with console access could potentially exploit this vulnerability to gain Filesystem access. This vulnerability only affects fresh installations of Collector versions earlier than 1.18.3. Systems that have been upgraded (either manually or automatically) to version 1.18.3 or later are not impacted, even if they were originally installed on an earlier version. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32652 Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged attacker with console access could potentially exploit this vulnerability to gain Filesystem access. This vulnerability only affects fresh installations of Collector versions earlier than 1.18.3. Systems that have been upgraded (either manually or automatically) to version 1.18.3 or later are not impacted, even if they were originally installed on an earlier version. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies empfiehlt allen Kunden, sowohl die CVSS-Gesamtbewertung als auch alle relevanten zeitlichen und umweltbezogenen Bewertungen zu berücksichtigen, die sich auf den potenziellen Schweregrad einer bestimmten Sicherheitsschwachstelle auswirken können.

Betroffene Produkte und Korrektur

Product Affected Versions Remediated Versions Link
Dell AIOps Collector Versions prior to 1.18.3 Version 1.18.3 or later https://www.dell.com/support/product-details/product/cloud-iq/drivers

 

Product Affected Versions Remediated Versions Link
Dell AIOps Collector Versions prior to 1.18.3 Version 1.18.3 or later https://www.dell.com/support/product-details/product/cloud-iq/drivers

 

Workarounds und Korrekturmaßnahmen

CVE ID Workaround and Mitigation
CVE-2026-32652

This vulnerability is exploitable only in fresh installations before 1.18.3 and have not undergone any upgrade (manual/automatic). If a collector instance has been upgraded at least once, no further action is required.

Below steps can be followed to remediate the vulnerability in case immediately upgrading the collector isn't possible:

  1. Reboot the collector and login into it through the auto login option in the boot menu (via vsphere console).
  2. Once login is successful, run the below commands:
    1. sudo passwd -d rancher # To delete the existing password for default user
    2. sudo passwd -l rancher # To lock the default user
  3. Once the above commands are successfully executed, it displays the message "Password expiry information changed". This makes sure that the workaround is successfully applied.

 

Revisionsverlauf

RevisionDateDescription
1.02026-06-16Initial Release

 

Zugehörige Informationen

Betroffene Produkte

CloudIQ
Artikeleigenschaften
Artikelnummer: 000477931
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 16 Juni 2026
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.