2 results (0.001 seconds)

CVSS: 9.8EPSS: 0%CPEs: 22EXPL: 0

Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable system with privileges of the compromised account. Dell EMC Networking X-Series versiones anteriores a 3.0.1.8 y Dell EMC PowerEdge VRTX Module, versiones de firrmware anteriores a 2.0.0.82, contienen una vulnerabilidad de Cifrado de Contraseña Débil. Un atacante remoto no autenticado podría explotar potencialmente esta vulnerabilidad, conllevando a una divulgación de determinadas credenciales de usuario. • https://www.dell.com/support/kbdoc/000185252 • CWE-261: Weak Encoding for Password CWE-326: Inadequate Encryption Strength •

CVSS: 8.1EPSS: 1%CPEs: 10EXPL: 2

Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEdge VRTX Switch Modules firmware versions 2.0.0.77 and older contain an information disclosure vulnerability. A remote unauthenticated attacker could exploit this vulnerability to retrieve sensitive data by sending a specially crafted request to the affected endpoints. Dell EMC Networking X-Series versiones de firmware 3.0.1.2 y anteriores, Dell EMC Networking PC5500 versiones de firmware 4.1.0.22 y anteriores y Dell EMC PowerEdge VRTX Switch Modules versiones de firmware 2.0.0.77 y anteriores, contienen una vulnerabilidad de divulgación de información. Un atacante no autenticado remoto podría explotar esta vulnerabilidad al recuperar datos confidenciales mediante el envío de una petición especialmente diseñada hacia los endpoints afectados. Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB suffer from an information leakage vulnerability. • https://www.exploit-db.com/exploits/51248 http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html https://www.dell.com/support/article/en-us/sln320366/dsa-2020-042-dell-emc-networking-security-update-for-an-information-disclosure-vulnerability?lang=en • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •