CVE-2019-3753
Summary
| CVE | CVE-2019-3753 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-20 19:15:00 UTC |
| Updated | 2020-10-16 14:49:00 UTC |
| Description | Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dell | Emc Powerconnect 7000 | - | All | All | All |
| Hardware | Dell | Emc Powerconnect 7000 | - | All | All | All |
| Operating System | Dell | Emc Powerconnect 7000 Firmware | All | All | All | All |
| Operating System | Dell | Emc Powerconnect 7000 Firmware | All | All | All | All |
| Hardware | Dell | Emc Powerconnect 8024 | - | All | All | All |
| Hardware | Dell | Emc Powerconnect 8024 | - | All | All | All |
| Operating System | Dell | Emc Powerconnect 8024 Firmware | All | All | All | All |
| Operating System | Dell | Emc Powerconnect 8024 Firmware | All | All | All | All |
| Hardware | Dell | Emc Powerconnect M6220 | - | All | All | All |
| Hardware | Dell | Emc Powerconnect M6220 | - | All | All | All |
| Operating System | Dell | Emc Powerconnect M6220 Firmware | All | All | All | All |
| Operating System | Dell | Emc Powerconnect M6220 Firmware | All | All | All | All |
| Hardware | Dell | Emc Powerconnect M6348 | - | All | All | All |
| Hardware | Dell | Emc Powerconnect M6348 | - | All | All | All |
| Operating System | Dell | Emc Powerconnect M6348 Firmware | All | All | All | All |
| Operating System | Dell | Emc Powerconnect M6348 Firmware | All | All | All | All |
| Hardware | Dell | Emc Powerconnect M8024 | - | All | All | All |
| Hardware | Dell | Emc Powerconnect M8024 | - | All | All | All |
| Hardware | Dell | Emc Powerconnect M8024-k | - | All | All | All |
| Hardware | Dell | Emc Powerconnect M8024-k | - | All | All | All |
| Operating System | Dell | Emc Powerconnect M8024-k Firmware | All | All | All | All |
| Operating System | Dell | Emc Powerconnect M8024-k Firmware | All | All | All | All |
| Operating System | Dell | Emc Powerconnect M8024 Firmware | All | All | All | All |
| Operating System | Dell | Emc Powerconnect M8024 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DSA-2019-124: Dell EMC PowerConnect Security Vulnerability | Dell US | CONFIRM | www.dell.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.