Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade at the earliest opportunity.
References
Configurations
Configuration 1 (hide)
|
History
03 Feb 2025, 20:52
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CPE | cpe:2.3:a:dell:openmanage_enterprise:4.0:*:*:*:*:*:*:* cpe:2.3:a:dell:openmanage_enterprise:4.0.1:*:*:*:*:*:*:* |
|
CWE | CWE-522 | |
References | () https://www.dell.com/support/kbdoc/en-us/000224251/dsa-2024-184-security-update-for-dell-openmanage-enterprise-vulnerability - Vendor Advisory | |
First Time |
Dell
Dell openmanage Enterprise |
29 Apr 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-29 09:15
Updated : 2025-02-03 20:52
NVD link : CVE-2024-28961
Mitre link : CVE-2024-28961
JSON object : View
Products Affected
dell
- openmanage_enterprise
CWE
CWE-522
Insufficiently Protected Credentials