CWE
798
Advisory Published
Updated

CVE-2017-14374

First published: Wed Dec 06 2017(Updated: )

The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with the knowledge of the password might potentially disable the SMI-S service via HTTP requests, affecting storage management and monitoring functionality via the SMI-S interface. This issue, aka DSM-30415, only affects a Windows installation of the Data Collector (not applicable to the virtual appliance).

Credit: security_alert@emc.com

Affected SoftwareAffected VersionHow to fix
Dell Storage Manager 2016<16.3.20

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2017-14374?

    CVE-2017-14374 is classified as a high severity vulnerability due to the potential for remote code execution and impact on storage management.

  • How do I fix CVE-2017-14374?

    To fix CVE-2017-14374, upgrade Dell Storage Manager to version 16.3.20 or later to eliminate the use of the hard-coded password.

  • What is vulnerable in CVE-2017-14374?

    CVE-2017-14374 affects Dell Storage Manager versions prior to 16.3.20 that utilize a hard-coded password for the SMI-S service.

  • Can CVE-2017-14374 be exploited remotely?

    Yes, CVE-2017-14374 can be exploited remotely by a user who knows the hard-coded password to disable the SMI-S service.

  • What is the impact of CVE-2017-14374?

    The impact of CVE-2017-14374 includes the potential disabling of the SMI-S service, which can disrupt storage management and monitoring functionality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203