Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgv4-5r2v-vqfp

Опубликовано: 03 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

EPSS

Процентиль: 29%
0.00103
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.4
nvd
больше 3 лет назад

Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

EPSS

Процентиль: 29%
0.00103
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-522