CVE Vulnerabilities

CVE-2021-21591

Insufficiently Protected Credentials

Published: Jul 12, 2021 | Modified: Oct 24, 2022
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Emc_unity_operating_environment Dell * 5.1.0.0.5.394 (excluding)
Emc_unity_xt_operating_environment Dell * 5.1.0.0.5.394 (excluding)
Emc_unityvsa_operating_environment Dell * 5.1.0.0.5.394 (excluding)

Potential Mitigations

References