CVE-2019-3753
Published: Aug 20, 2019
Modified: Sep 16, 2024
CVSS v3.0
7.2
Description
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.
| Vendor | Product | Versions |
|---|---|---|
Dell EMC | PowerConnect 8024 | affected unspecified - < 5.1.15.2 |
Dell EMC | PowerConnect 7000 | affected unspecified - < 5.1.15.2 |
Dell EMC | PowerConnect M6348 | affected unspecified - < 5.1.15.2 |
Dell EMC | PowerConnect M6220 | affected unspecified - < 5.1.15.2 |
Dell EMC | PowerConnect M8024 | affected unspecified - < 5.1.15.2 |
Dell EMC | PowerConnect M8024-K | affected unspecified - < 5.1.15.2 |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now