Plain-Text Password Vulnerability in Dell EMC PowerStore
CVE-2020-29501

6.4MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
5 January 2021

Summary

Dell EMC PowerStore versions below 1.0.3.0.5.007 are susceptible to a vulnerability that involves storing user credentials in plain text. This flaw can be exploited by a locally authenticated attacker to extract sensitive passwords, potentially granting unauthorized access to the application with the privileges of the compromised account. It highlights the critical need for secure password management practices within PowerStore environments.

Affected Version(s)

PowerStore < unspecified

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.