CVE Vulnerabilities

CVE-2018-1241

Insertion of Sensitive Information into Log File

Published: May 29, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password to use it in further attacks.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Recoverpoint Emc * 5.1.2 (excluding)
Recoverpoint_for_virtual_machines Emc * 5.1.1.3 (excluding)

Potential Mitigations

References