CVE-2024-28961
Severity CVSS v4.0:
Pending analysis
Type:
CWE-256
Plaintext Storage of a Password
Publication date:
29/04/2024
Last modified:
03/02/2025
Description
Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade at the earliest opportunity.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:dell:openmanage_enterprise:4.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:dell:openmanage_enterprise:4.0.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



