CVE-2024-37135

DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:dm5500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:dm5500:-:*:*:*:*:*:*:*

History

22 Nov 2024, 18:15

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000227424/dsa-2024-290-security-update-for-dell-powerprotect-data-manager-appliance-dm5500-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000227424/dsa-2024-290-security-update-for-dell-powerprotect-data-manager-appliance-dm5500-for-multiple-vulnerabilities - Vendor Advisory
CPE cpe:2.3:o:dell:dm5500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:dm5500:-:*:*:*:*:*:*:*
First Time Dell
Dell dm5500
Dell dm5500 Firmware
CWE NVD-CWE-Other

01 Aug 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) DM5500 5.16.0.0, contiene una vulnerabilidad de divulgación de información. Un atacante local con altos privilegios podría explotar esta vulnerabilidad, lo que daría lugar a la divulgación de determinadas credenciales de usuario. Es posible que el atacante pueda utilizar las credenciales expuestas para acceder a la aplicación vulnerable con los privilegios de la cuenta comprometida.

31 Jul 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-31 14:15

Updated : 2024-11-22 18:15


NVD link : CVE-2024-37135

Mitre link : CVE-2024-37135

CVE.ORG link : CVE-2024-37135


JSON object : View

Products Affected

dell

  • dm5500_firmware
  • dm5500
CWE
CWE-256

Unprotected Storage of Credentials

NVD-CWE-Other