Password Management Flaw in Unisys Stealth
CVE-2021-28492

4.9MEDIUM

Key Information:

Vendor

Unisys

Status
Vendor
CVE Published:
20 April 2021

What is CVE-2021-28492?

The Unisys Stealth product line has a vulnerability where passwords are stored in a format that is recoverable, posing a serious threat to user accounts and sensitive information. Attackers may exploit this weakness to gain unauthorized access by retrieving stored passwords. It is crucial for users of Unisys Stealth versions 5.x, 5.1.x, and 6.x prior to their respective patch versions to update their systems to mitigate this risk.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.