Vulnerability record · CVE-2017-14374 · published 6 December 2017
CVE-2017-14374: Dell storage manager hard-coded credentials vulnerability
Dell · Storage Manager
The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with the knowledge of the password might potentially disable the SMI-S service via HTTP requests, affecting storage management and monitoring functionality via the SMI-S interface. This issue, aka DSM-30415, only affects a Windows installation of the Data Collector (not applicable to the virtual appliance).
Description
The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with the knowledge of the password might potentially disable the SMI-S service via HTTP requests, affecting storage management and monitoring functionality via the SMI-S interface. This issue, aka DSM-30415, only affects a Windows installation of the Data Collector (not applicable to the virtual appliance).
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://topics-cdn.dell.com/pdf/storage-sc2000_release%20notes24_en-us.pdf | Release NotesVendor Advisory |
| http://topics-cdn.dell.com/pdf/storage-sc2000_release%20notes24_en-us.pdf | Release NotesVendor Advisory |
Track CVE-2017-14374 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-14374), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.