Plain-text Password Vulnerability in Dell Networker Products
CVE-2024-22432

7.8HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
25 January 2024

Summary

The Dell Networker software, specifically version 19.9 and earlier, has a security vulnerability that involves the storage of user passwords in plain-text format within temporary configuration files during the backup process of MySQL databases. This design flaw grants users with low privilege access the potential to exploit this weakness. By leveraging their access, attackers could gain visibility into sensitive MySQL database user credentials, which may lead to unauthorized access to the associated application database. The implications of this weakness underscore the importance of secure credential management and safeguarding database access.

Affected Version(s)

NetWorker Module for Databases and Applications - Oracle 19.9 <= 19.9.0.3

NetWorker Module for Databases and Applications - Oracle 19.8 <= 19.8.0.4

NetWorker Module for Databases and Applications - Oracle 19.7 <= 19.7.0.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.