CVE Vulnerabilities

CVE-2024-28961

Plaintext Storage of a Password

Published: Apr 29, 2024 | Modified: Feb 03, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade at the earliest opportunity.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Affected Software

NameVendorStart VersionEnd Version
Openmanage_enterpriseDell4.0 (including)4.0 (including)
Openmanage_enterpriseDell4.0.1 (including)4.0.1 (including)

Potential Mitigations

References