CVE-2024-28961

Severity CVSS v4.0:
Pending analysis
Type:
CWE-256 Plaintext Storage of a Password
Publication date:
29/04/2024
Last modified:
03/02/2025

Description

Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade at the earliest opportunity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:openmanage_enterprise:4.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:openmanage_enterprise:4.0.1:*:*:*:*:*:*:*