First published: Mon Jan 20 2014(Updated: )
The login page in the GoAhead web server on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device outage) via a long username.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dell PowerConnect 3348 | =1.2.1.3 | |
Dell PowerConnect 3524P | =2.0.0.48 | |
Dell PowerConnect 5324 | =2.0.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3606 has a severity rating that indicates it can lead to a denial of service condition.
To mitigate CVE-2013-3606, ensure you update the affected Dell PowerConnect switches to the latest firmware version.
CVE-2013-3606 affects the Dell PowerConnect 3348, 3524P, and 5324 switches with specific firmware versions.
CVE-2013-3606 allows remote attackers to execute a denial of service attack through inputting a long username.
As a temporary workaround for CVE-2013-3606, limit access to the login page or use network firewalls to filter traffic.