DSA-2026-231: Security Update for Dell AIOps Collector for Default Credential Vulnerability

Riepilogo: Dell AIOps Collector remediation is available for use of default credentials that could be exploited by malicious users to compromise the affected system.

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Impatto

High

Dettagli

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32652 Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged attacker with console access could potentially exploit this vulnerability to gain Filesystem access. This vulnerability only affects fresh installations of Collector versions earlier than 1.18.3. Systems that have been upgraded (either manually or automatically) to version 1.18.3 or later are not impacted, even if they were originally installed on an earlier version. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32652 Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged attacker with console access could potentially exploit this vulnerability to gain Filesystem access. This vulnerability only affects fresh installations of Collector versions earlier than 1.18.3. Systems that have been upgraded (either manually or automatically) to version 1.18.3 or later are not impacted, even if they were originally installed on an earlier version. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies raccomanda a tutti i clienti di prendere in considerazione sia il punteggio base CVSS, sia ogni eventuale punteggio temporale o ambientale che possa avere effetti sul livello di gravità potenziale associato a una specifica vulnerabilità di sicurezza.

Prodotti interessati e correzione

Product Affected Versions Remediated Versions Link
Dell AIOps Collector Versions prior to 1.18.3 Version 1.18.3 or later https://www.dell.com/support/product-details/product/cloud-iq/drivers

 

Product Affected Versions Remediated Versions Link
Dell AIOps Collector Versions prior to 1.18.3 Version 1.18.3 or later https://www.dell.com/support/product-details/product/cloud-iq/drivers

 

Soluzioni alternative e mitigazioni

CVE ID Workaround and Mitigation
CVE-2026-32652

This vulnerability is exploitable only in fresh installations before 1.18.3 and have not undergone any upgrade (manual/automatic). If a collector instance has been upgraded at least once, no further action is required.

Below steps can be followed to remediate the vulnerability in case immediately upgrading the collector isn't possible:

  1. Reboot the collector and login into it through the auto login option in the boot menu (via vsphere console).
  2. Once login is successful, run the below commands:
    1. sudo passwd -d rancher # To delete the existing password for default user
    2. sudo passwd -l rancher # To lock the default user
  3. Once the above commands are successfully executed, it displays the message "Password expiry information changed". This makes sure that the workaround is successfully applied.

 

Cronologia delle revisioni

RevisionDateDescription
1.02026-06-16Initial Release

 

Informazioni correlate

Prodotti interessati

CloudIQ
Proprietà dell'articolo
Numero articolo: 000477931
Tipo di articolo: Dell Security Advisory
Ultima modifica: 16 giu 2026
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.