Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx3v-3576-98m4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

EPSS

Процентиль: 31%
0.00116
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-312
CWE-522

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

EPSS

Процентиль: 31%
0.00116
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-312
CWE-522