CVE Vulnerabilities

CVE-2024-28961

Plaintext Storage of a Password

Published: Apr 29, 2024 | Modified: Feb 03, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade at the earliest opportunity.

Weakness

Storing a password in plaintext may result in a system compromise.

Affected Software

Name Vendor Start Version End Version
Openmanage_enterprise Dell 4.0 (including) 4.0 (including)
Openmanage_enterprise Dell 4.0.1 (including) 4.0.1 (including)

Potential Mitigations

References