First published: Mon Jan 20 2014(Updated: )
The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device reset) or possibly execute arbitrary code by sending many packets to TCP port 22.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dell PowerConnect 3348 | =1.2.1.3 | |
Dell PowerConnect 3524P | =2.0.0.48 | |
Dell PowerConnect 5324 | =2.0.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3594 is classified as a high severity vulnerability due to its potential to cause denial of service and execute arbitrary code.
To fix CVE-2013-3594, update the affected Dell PowerConnect switch firmware to the latest version available from Dell.
CVE-2013-3594 affects Dell PowerConnect 3348 (version 1.2.1.3), 3524P (version 2.0.0.48), and 5324 (version 2.0.1.4) switches.
CVE-2013-3594 can be exploited by remote attackers to launch denial of service attacks or potentially execute arbitrary code.
While there is no specific information on active exploitation of CVE-2013-3594, it is advisable to mitigate the risk as it has a significant impact potential.