Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-28971


Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.


Published

2024-05-08T16:15:08.747

Last Modified

2025-01-27T18:43:23.280

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 3.5 (LOW)

Weaknesses
  • Type: Secondary
    CWE-256
  • Type: Primary
    CWE-522

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell openmanage_enterprise_update_manager < 1.5.1 Yes

References