Plain-Text Password Storage Vulnerability in Dell EMC Repository Manager
CVE-2022-26856

8.2HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
21 April 2022

Summary

A vulnerability exists in Dell EMC Repository Manager version 3.4.0, which allows local attackers to access stored passwords in plain text. This weakness may enable an attacker to reveal user credentials, leading to potential unauthorized access to the application’s database with the permissions of the affected account. It is crucial for users to be aware of this security issue and implement recommended mitigation strategies to safeguard their sensitive information.

Affected Version(s)

Dell Repository Manager (DRM) < unspecified

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.