DSA-2024-209: Security Update for Dell Update Manager Plugin Vulnerability
Résumé: Dell Update Manager Plugin remediation is available for plaintext password vulnerability in Log file that could be exploited by malicious users to compromise the affected system.
Cet article concerne
Cet article ne concerne pas
Cet article n’est associé à aucun produit spécifique.
Toutes les versions du produit ne sont pas identifiées dans cet article.
Impact
Low
Détails
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-28971 | Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. | 3.5 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-28971 | Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. | 3.5 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N |
Produits concernés et mesure corrective
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell Update Manager Plugin | Versions 1.4.0 through 1.5.0 | 1.5.1 | Dell OpenManage Enterprise Update Managerv1.5.1 | Driver Details | Dell US |
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell Update Manager Plugin | Versions 1.4.0 through 1.5.0 | 1.5.1 | Dell OpenManage Enterprise Update Managerv1.5.1 | Driver Details | Dell US |
No action required from the customer if UMP-1.5.1 is already installed by the customer. However, we recommend following the workaround mentioned above.
Solutions de contournement et mesures d’atténuation
| CVE ID | Workaround and Mitigation |
|---|---|
| CVE-2024-28971 | Remove logs from UMP |
Historique des révisions
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-05-07 | Initial release |
| 2.0 | 2025-04-15 | Added product tagging for better classification |
Informations connexes
Mention légale
Produits concernés
OpenManage Enterprise Update ManagerPropriétés de l’article
Numéro d’article: 000224849
Type d’article: Dell Security Advisory
Dernière modification: 15 avr. 2025
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.