Plain-Text Password Storage Vulnerability in Dell Unity Products
CVE-2022-29085
6.4MEDIUM
Summary
A vulnerability has been identified in Dell Unity, Dell UnityVSA, and Dell Unity XT products that allows plain-text storage of passwords when certain off-array tools are executed. This flaw affects versions prior to 5.2.0.0.5.173, potentially enabling a local malicious user with elevated privileges to access sensitive credentials stored in plain text. If exploited, this can lead to unauthorized access and control over the system, significantly increasing the risk of further attacks.
Affected Version(s)
Unity < 5.2.0.0.5.173
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved