« Volver al listado

CVE-2019-3753

Estado: ModificadaMedia (6.5)—

Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-3753",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell EMC",
          "product": "PowerConnect 8024",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.1.15.2",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Dell EMC",
          "product": "PowerConnect 7000",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.1.15.2",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Dell EMC",
          "product": "PowerConnect M6348",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.1.15.2",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Dell EMC",
          "product": "PowerConnect M6220",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.1.15.2",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Dell EMC",
          "product": "PowerConnect M8024",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.1.15.2",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Dell EMC",
          "product": "PowerConnect  M8024-K",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.1.15.2",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-08-20T19:15:11.357",
  "references": [
    {
      "url": "https://www.dell.com/support/article/sln318359/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/article/sln318359/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-312"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks."
    },
    {
      "lang": "es",
      "value": "Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 y M8024-K que ejecutan versiones de firmware anteriores a 5.1.15.2 contienen una vulnerabilidad de almacenamiento de contraseñas de texto sin formato. Las credenciales de TACACS-Radius se salvan en texto sin formato en el menú de configuración del sistema. Un usuario malintencionado autenticado con acceso al menú de configuración del sistema puede obtener la contraseña expuesta para usarla en otros ataques."
    }
  ],
  "lastModified": "2026-06-17T02:35:31.927",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerconnect_8024_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBA79D17-3E60-43E6-8B42-F829A78392CA",
              "versionEndExcluding": "5.1.15.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerconnect_8024:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AAF4828A-77DD-46E6-A819-44228AD77733"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerconnect_7000_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF37213A-99CE-4BE3-920E-828959809AE2",
              "versionEndExcluding": "5.1.15.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerconnect_7000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "212728FB-B600-48A2-B5A4-C8EF031A7A97"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerconnect_m6348_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EB215A4-E2F7-4E6E-AD9D-33B8A17AC05A",
              "versionEndExcluding": "5.1.15.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerconnect_m6348:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D230A1B5-2306-401E-AF05-8E5A98A2AFCE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerconnect_m6220_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF797E0F-C862-47D0-98BF-E31B7ACAB4AF",
              "versionEndExcluding": "5.1.15.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerconnect_m6220:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3266F2A2-236A-4B59-B701-0746A42E59B5"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerconnect_m8024_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "695A5626-E4F1-4673-8C85-98A17B79541A",
              "versionEndExcluding": "5.1.15.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerconnect_m8024:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "07F3D2B1-1EE3-4811-AB31-E44785940D72"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerconnect_m8024-k_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "217D0A5B-3C90-445B-8CA6-071D3A8D8D69",
              "versionEndExcluding": "5.1.15.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerconnect_m8024-k:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "185331ED-3965-430F-A26E-54E2EC12C787"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}