5.5
CVE-2026-70414
- EPSS 0.1%
- Veröffentlicht 06.10.2026 18:46:23
- Zuletzt bearbeitet 07.10.2026 15:17:48
- Erkennungen
Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerDell
≫
Produkt
Command | Configure (DCC)
Default Statusunaffected
Version
0
Version <
5.2.3.35
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.008 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| EMC | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-256 Plaintext Storage of a Password
The product stores a password in plaintext within resources such as memory or files.
https://www.dell.com/support/kbdoc/en-us/000502471/dsa-2026-378-security-update-for-dell-command-configure-for-multiple-vulnerabilities