Clear Text Credential Exposure in EMC ScaleIO by Dell Technologies
CVE-2017-8001
8.4HIGH
Summary
A security issue has been found in EMC ScaleIO 2.0.1.x where a support script inadvertently saves the credentials for the ScaleIO MDM user in plain text within temporary log files. This exposure allows unprivileged users, who have access to the server, to read these temporary files and potentially recover sensitive credentials, which could lead to unauthorized access and compromise system integrity.
Affected Version(s)
EMC ScaleIO EMC ScaleIO 2.0.1.x EMC ScaleIO EMC ScaleIO 2.0.1.x
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved