Plain-text Password Storage Vulnerability in Dell VxRail Manager
CVE-2021-21508

6.7MEDIUM

Key Information:

Vendor

Dell

Status
Vendor
CVE Published:
22 May 2026

What is CVE-2021-21508?

Dell VxRail versions prior to 7.0.200 present a vulnerability in VxRail Manager that allows for the storage of passwords in plain text. This security flaw can be exploited by a system administrator, leading to the potential exposure of sensitive user credentials. An attacker with these credentials may gain unauthorized access to the affected application with the same privileges as the compromised account, posing a significant security risk to the affected systems.

Affected Version(s)

VxRail 0 < 7.0.200

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.