PT-2021-12388 · Dell Emc · Dell Repository Manager
Published
2021-07-19
·
Updated
2021-08-02
·
CVE-2020-5315
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell EMC Repository Manager (DRM) version 3.2
Description
The issue concerns a plain-text password storage vulnerability. Specifically, the proxy server user password is stored in plain text in a local database. A local authenticated malicious user with access to the local file system may exploit the exposed password to gain access with the privileges of the compromised user.
Recommendations
For Dell EMC Repository Manager (DRM) version 3.2, consider restricting access to the local file system to minimize the risk of exploitation. As a temporary workaround, limit the privileges of users who have access to the local database to reduce potential damage. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Repository Manager