DSA-2019-124: Dell EMC PowerConnect Security Vulnerability

Сводка: Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K firmware has been updated to address a vulnerability which may be potentially exploited to compromise the system.

Данная статья применяется к Данная статья не применяется к Эта статья не привязана к какому-либо конкретному продукту. В этой статье указаны не все версии продуктов.

Влияние

High

Подробные сведения

Dell PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

CVSS Base Score:7.2 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Dell PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

CVSS Base Score:7.2 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Dell рекомендует всем клиентам учитывать как базовую оценку CVSS, так и любые временные и обусловленные средой оценки, которые могут повлиять на потенциальную степень серьезности конкретной уязвимости.

Затронутые продукты и исправление

Affected products:

The below Dell EMC PowerConnect models running firmware versions prior to 5.1.15.2: 

  • 8024
  • 7000
  • M6348
  • M6220
  • M8024
  • M8024-K

Remediation:

The following Dell EMC PowerConnect firmware release contains a resolution to the vulnerability:

  •     Dell EMC PowerConnect firmware version 5.1.15.2 and later.

Customers can download the latest firmware version at the support site for their respective model below:

  Dell EMC recommends all customers upgrade at the earliest opportunity. 
 

Affected products:

The below Dell EMC PowerConnect models running firmware versions prior to 5.1.15.2: 

  • 8024
  • 7000
  • M6348
  • M6220
  • M8024
  • M8024-K

Remediation:

The following Dell EMC PowerConnect firmware release contains a resolution to the vulnerability:

  •     Dell EMC PowerConnect firmware version 5.1.15.2 and later.

Customers can download the latest firmware version at the support site for their respective model below:

  Dell EMC recommends all customers upgrade at the earliest opportunity. 
 

Сведения об авторе и авторских правах

Dell EMC would like to thank Daniel Cobb (@droctapus1) for reporting this vulnerability.

Связанная информация

Затронутые продукты

PowerConnect M6220, PowerConnect M6348, PowerConnect M8024, PowerConnect M8024-K
Свойства статьи
Номер статьи: 000125969
Тип статьи: Dell Security Advisory
Последнее изменение: 05 Jun 2025
Получите ответы на свои вопросы от других пользователей Dell
Услуги технической поддержки
Проверьте, распространяются ли на ваше устройство услуги технической поддержки.