Plain-Text Password Storage Vulnerability in Dell Unity Products
CVE-2022-29085

6.4MEDIUM

Key Information:

Vendor
Dell
Status
Vendor
CVE Published:
2 June 2022

Summary

A vulnerability has been identified in Dell Unity, Dell UnityVSA, and Dell Unity XT products that allows plain-text storage of passwords when certain off-array tools are executed. This flaw affects versions prior to 5.2.0.0.5.173, potentially enabling a local malicious user with elevated privileges to access sensitive credentials stored in plain text. If exploited, this can lead to unauthorized access and control over the system, significantly increasing the risk of further attacks.

Affected Version(s)

Unity < 5.2.0.0.5.173

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.