CVE-2026-70414: Medium severity Dell Dell Command Configure vulnerability
Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Command | Configure (DCC)to a version that resolves this vulnerability.Fixed in 5.2.3.35
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems running Dell Command | Configure versions earlier than 5.2.3.35 are affected. Exploitation requires local access and a low-privileged account.
What can an attacker gain from successful exploitation?
A successful attack could disclose password information stored in plaintext. The provided severity vector indicates no impact to integrity or availability.
What version addresses the vulnerability?
Upgrade Dell Command | Configure to version 5.2.3.35 or later.