Description


Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

Weaknesses



CWE-256


CWE-312

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

6 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-03-04T20:15:09.450Z

4 years ago

Last modified

2024-11-21T05:29:30.060Z

1 year ago