Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Emc_unity_operating_environment | Dell | * | 5.1.0.0.5.394 (excluding) |
Emc_unity_xt_operating_environment | Dell | * | 5.1.0.0.5.394 (excluding) |
Emc_unityvsa_operating_environment | Dell | * | 5.1.0.0.5.394 (excluding) |