Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22432

Опубликовано: 25 янв. 2024
Источник: nvd
CVSS3: 7.8
CVSS3: 6.5
EPSS Низкий

Описание

Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the disclosure of configured MySQL Database user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application Database with privileges of the compromised account.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dell:networker:*:*:*:*:*:*:*:*
Версия до 19.9 (включая)

EPSS

Процентиль: 18%
0.00058
Низкий

7.8 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-256
CWE-522

Связанные уязвимости

CVSS3: 7.8
github
около 2 лет назад

Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the disclosure of configured MySQL Database user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application Database with privileges of the compromised account.

CVSS3: 7.8
fstec
около 2 лет назад

Уязвимость системы резервного копирования и восстановления данных Dell EMC NetWorker, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить регистрационные данные пользователя

EPSS

Процентиль: 18%
0.00058
Низкий

7.8 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-256
CWE-522