Executive brief
Dell VxRail appliances contain a script used for disk and power supply unit (PSU) maintenance that requires passwords to be provided in plain text. This could allow a highly privileged local user to discover sensitive credentials, potentially leading to further unauthorized access or system compromise. Organizations should update to version 7.0.520 to resolve this issue.
Technical details
A plaintext password storage vulnerability (CWE-256) exists in the Dell VxRail update_disk_psu_baseline.sh script. The script requires passwords to be provided in plain text, which can lead to credential exposure. An attacker with high privileges and local access to the system could exploit this to retrieve sensitive information. The vulnerability has a CVSS score of 7.4, reflecting that while it requires high privileges and complex conditions (AC:H), it can impact the integrity and availability of the system across security scopes. Dell has released VxRail version 7.0.520 to address this flaw.
Affected products
- Dell VxRail Appliance 7.0.x versions prior to 7.0.520
Timeline
- 2024-06-20: advisory: Initial release of Dell Security Advisory DSA-2024-247
- 2026-06-16: disclosed: CVE published to NVD dataset