Plain-text Password Vulnerability in Dell Networker Products
CVE-2024-22432
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 25 January 2024
Summary
The Dell Networker software, specifically version 19.9 and earlier, has a security vulnerability that involves the storage of user passwords in plain-text format within temporary configuration files during the backup process of MySQL databases. This design flaw grants users with low privilege access the potential to exploit this weakness. By leveraging their access, attackers could gain visibility into sensitive MySQL database user credentials, which may lead to unauthorized access to the associated application database. The implications of this weakness underscore the importance of secure credential management and safeguarding database access.
Affected Version(s)
NetWorker Module for Databases and Applications - Oracle 19.9 <= 19.9.0.3
NetWorker Module for Databases and Applications - Oracle 19.8 <= 19.8.0.4
NetWorker Module for Databases and Applications - Oracle 19.7 <= 19.7.0.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved