Plaintext Password Storage Vulnerability in Dell VxRail
CVE-2025-21102

4.4MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
8 January 2025

Summary

Dell VxRail software versions 7.0.000 through 7.0.532 are impacted by a vulnerability that allows for the insecure storage of passwords in plaintext. This flaw could be exploited by attackers with local access who have high privileges, potentially leading to unauthorized information exposure. Organizations using affected versions should prioritize remediation to mitigate risks associated with this vulnerability.

Affected Version(s)

Dell VxRail HCI 7.0.000 <= 7.0.532

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.