PT-2021-11673 · Dell · Dell Emc Unity+2

Published

2021-01-05

·

Updated

2021-01-12

·

CVE-2020-29489

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012
Description: The issue concerns a plain-text password storage vulnerability. A user's credentials, including the Unisphere admin privilege user's password, are stored in plain text in a system file. A local authenticated attacker with access to the system files may use the exposed password to gain access with the privileges of the compromised user.
Recommendations: For versions prior to 5.0.4.0.5.012, update to version 5.0.4.0.5.012 or later to resolve the issue. As a temporary workaround, consider restricting access to system files to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29489

Affected Products

Dell Emc Unity
Unity Xt
Unityvsa