CVE-2017-14374
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with the knowledge of the password might potentially disable the SMI-S service via HTTP requests, affecting storage management and monitoring functionality via the SMI-S interface. This issue, aka DSM-30415, only affects a Windows installation of the Data Collector (not applicable to the virtual appliance).
El servicio SMI-S en Dell Storage Manager en versiones anteriores a la 16.3.20 (también conocida como 2016 R3.20) está protegido mediante el uso de una contraseña embebida. Un usuario remoto que conozca la contraseña podría deshabilitar el servicio SMI-S mediante peticiones HTTP. Esto afectaría a la gestión de contraseñas y a la funcionalidad de monitorización mediante la interfaz SMI-S. Este problema, también conocido como DSM-30415, solo afecta a la instalación de Windows del recopilador de datos (no aplicable a la aplicación virtual).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-09-12 CVE Reserved
- 2017-12-06 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://topics-cdn.dell.com/pdf/storage-sc2000_release%20notes24_en-us.pdf | 2017-12-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Storage Manager Search vendor "Dell" for product "Storage Manager" | < 16.3.20 Search vendor "Dell" for product "Storage Manager" and version " < 16.3.20" | - |
Affected
|