Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mj3-mj87-cf2h

Опубликовано: 25 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the disclosure of configured MySQL Database user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application Database with privileges of the compromised account.

Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the disclosure of configured MySQL Database user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application Database with privileges of the compromised account.

EPSS

Процентиль: 18%
0.00058
Низкий

7.8 High

CVSS3

Дефекты

CWE-256
CWE-522

Связанные уязвимости

CVSS3: 7.8
nvd
около 2 лет назад

Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the disclosure of configured MySQL Database user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application Database with privileges of the compromised account.

CVSS3: 7.8
fstec
около 2 лет назад

Уязвимость системы резервного копирования и восстановления данных Dell EMC NetWorker, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить регистрационные данные пользователя

EPSS

Процентиль: 18%
0.00058
Низкий

7.8 High

CVSS3

Дефекты

CWE-256
CWE-522