CVE Vulnerabilities

CVE-2021-42371

Insecure Storage of Sensitive Information

Published: Nov 08, 2021 | Modified: Sep 03, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Lpar2rrd Xorux * 7.30 (excluding)
Stor2rrd Xorux * 7.30 (excluding)

References