PT-2021-12388 · Dell Emc · Dell Repository Manager

Published

2021-07-19

·

Updated

2021-08-02

·

CVE-2020-5315

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC Repository Manager (DRM) version 3.2
Description The issue concerns a plain-text password storage vulnerability. Specifically, the proxy server user password is stored in plain text in a local database. A local authenticated malicious user with access to the local file system may exploit the exposed password to gain access with the privileges of the compromised user.
Recommendations For Dell EMC Repository Manager (DRM) version 3.2, consider restricting access to the local file system to minimize the risk of exploitation. As a temporary workaround, limit the privileges of users who have access to the local database to reduce potential damage. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5315

Affected Products

Dell Repository Manager