ID

VAR-201401-0097


CVE

CVE-2013-3595


TITLE

Dell PowerConnect 3348, 3524p, and 5324 switches are vulnerable to denial-of-service attacks

Trust: 0.8

sources: CERT/CC: VU#122582

DESCRIPTION

The OpenManage web application 2.5 build 1.19 on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote authenticated users to cause a denial of service (device reset) via a direct request to an unspecified OSPF URL. Dell PowerConnect 3348 version 1.2.1.3, PowerConnect 3524p version 2.0.0.48, PowerConnect 5324 version 2.0.1.4, and possibly earlier versions contain a denial-of-service (CWE-20) vulnerability.Dell OpenManage web application version 2.5 Build No. 1.19 and possibly earlier versions contain a denial-of-service (CWE-20) vulnerability.Dell GoAhead web server login page also contains a denial-of-service (CWE-20) vulnerability. Dell OpenManage allows administrators to manage, monitor, and manipulate Dell PowerEdge servers from a central location or remotely. This page cannot be accessed from the web application link but can be found in the firmware. Successful exploits will cause the crash and reset the switch, resulting in a denial-of-service condition. Dell PowerConnect 3348, 3524p and 5324 are all series switch products of Dell (Dell). The following series of switches and versions are affected: Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, 5324 2.0.1.4

Trust: 3.24

sources: NVD: CVE-2013-3595 // CERT/CC: VU#122582 // JVNDB: JVNDB-2014-001215 // CNVD: CNVD-2014-00466 // BID: 65081 // VULHUB: VHN-63597

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-00466

AFFECTED PRODUCTS

vendor:dellmodel:powerconnect 3524pscope:eqversion:2.0.0.48

Trust: 2.5

vendor:dellmodel:powerconnect 5324scope:eqversion:2.0.1.4

Trust: 1.6

vendor:dellmodel:powerconnect 3348scope:eqversion:1.2.1.3

Trust: 1.6

vendor:dellmodel:powerconnectscope:eqversion:33481.2.1.3

Trust: 0.9

vendor:dellmodel:powerconnectscope:eqversion:53242.0.1.4

Trust: 0.9

vendor:dell computermodel: - scope: - version: -

Trust: 0.8

vendor:dellmodel:openmanage web applicationscope:lteversion:2.5 build no. 1.19

Trust: 0.8

vendor:dellmodel:powerconnect 3348scope:lteversion:firmware 1.2.1.3

Trust: 0.8

vendor:dellmodel:powerconnect 3524pscope:lteversion:firmware 2.0.0.48

Trust: 0.8

vendor:dellmodel:powerconnect 5324scope:lteversion:firmware 2.0.1.4

Trust: 0.8

vendor:dellmodel:goahead web serverscope: - version: -

Trust: 0.6

vendor:dellmodel:openmanage web application build no.scope:eqversion:2.51.19

Trust: 0.3

sources: CERT/CC: VU#122582 // CNVD: CNVD-2014-00466 // BID: 65081 // JVNDB: JVNDB-2014-001215 // CNNVD: CNNVD-201401-382 // NVD: CVE-2013-3595

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-3595
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-3595
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-00466
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201401-382
value: MEDIUM

Trust: 0.6

VULHUB: VHN-63597
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-3595
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-00466
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-63597
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-00466 // VULHUB: VHN-63597 // JVNDB: JVNDB-2014-001215 // CNNVD: CNNVD-201401-382 // NVD: CVE-2013-3595

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 2.7

sources: CERT/CC: VU#122582 // VULHUB: VHN-63597 // JVNDB: JVNDB-2014-001215 // NVD: CVE-2013-3595

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201401-382

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201401-382

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001215

PATCH

title:PowerConnect 3524Purl:http://www.dell.com/support/drivers/us/en/04/Product/powerconnect-3524p

Trust: 0.8

title:PowerConnect 5324url:http://www.dell.com/support/drivers/us/en/04/Product/powerconnect-5324

Trust: 0.8

title:PowerConnect 3348url:http://www.dell.com/support/drivers/us/en/04/Product/powerconnect-3348

Trust: 0.8

sources: JVNDB: JVNDB-2014-001215

EXTERNAL IDS

db:CERT/CCid:VU#122582

Trust: 4.2

db:NVDid:CVE-2013-3595

Trust: 3.4

db:JVNid:JVNVU95569358

Trust: 0.8

db:JVNDBid:JVNDB-2014-001215

Trust: 0.8

db:CNVDid:CNVD-2014-00466

Trust: 0.6

db:CNNVDid:CNNVD-201401-382

Trust: 0.6

db:BIDid:65081

Trust: 0.4

db:VULHUBid:VHN-63597

Trust: 0.1

sources: CERT/CC: VU#122582 // CNVD: CNVD-2014-00466 // VULHUB: VHN-63597 // BID: 65081 // JVNDB: JVNDB-2014-001215 // CNNVD: CNNVD-201401-382 // NVD: CVE-2013-3595

REFERENCES

url:http://www.kb.cert.org/vuls/id/122582

Trust: 3.4

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/90597

Trust: 1.1

url:http://cwe.mitre.org/data/definitions/20.html

Trust: 0.8

url:http://www.dell.com/support/drivers/us/en/04/product/powerconnect-3348

Trust: 0.8

url:http://www.dell.com/support/drivers/us/en/04/product/powerconnect-3524p

Trust: 0.8

url:http://www.dell.com/support/drivers/us/en/04/product/powerconnect-5324

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-3595

Trust: 0.8

url:http://jvn.jp/vu/jvnvu95569358

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-3595

Trust: 0.8

url:http://dell.com

Trust: 0.3

sources: CERT/CC: VU#122582 // CNVD: CNVD-2014-00466 // VULHUB: VHN-63597 // BID: 65081 // JVNDB: JVNDB-2014-001215 // CNNVD: CNNVD-201401-382 // NVD: CVE-2013-3595

CREDITS

Rijnard van Tonder

Trust: 0.3

sources: BID: 65081

SOURCES

db:CERT/CCid:VU#122582
db:CNVDid:CNVD-2014-00466
db:VULHUBid:VHN-63597
db:BIDid:65081
db:JVNDBid:JVNDB-2014-001215
db:CNNVDid:CNNVD-201401-382
db:NVDid:CVE-2013-3595

LAST UPDATE DATE

2025-04-11T22:48:24.518000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#122582date:2014-01-17T00:00:00
db:CNVDid:CNVD-2014-00466date:2014-01-21T00:00:00
db:VULHUBid:VHN-63597date:2017-08-29T00:00:00
db:BIDid:65081date:2014-01-17T00:00:00
db:JVNDBid:JVNDB-2014-001215date:2014-01-22T00:00:00
db:CNNVDid:CNNVD-201401-382date:2014-01-26T00:00:00
db:NVDid:CVE-2013-3595date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CERT/CCid:VU#122582date:2014-01-17T00:00:00
db:CNVDid:CNVD-2014-00466date:2014-01-21T00:00:00
db:VULHUBid:VHN-63597date:2014-01-20T00:00:00
db:BIDid:65081date:2014-01-17T00:00:00
db:JVNDBid:JVNDB-2014-001215date:2014-01-22T00:00:00
db:CNNVDid:CNNVD-201401-382date:2014-01-26T00:00:00
db:NVDid:CVE-2013-3595date:2014-01-20T04:58:49.680