PT-2021-14644 · Dell Emc · Idpa+1
Published
2021-08-10
·
Updated
2021-08-18
·
CVE-2021-21601
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell EMC Data Protection Search versions 19.4 and prior
IDPA versions 2.6.1 and prior
Description
The issue allows a local low privileged attacker to potentially exploit it, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with the privileges of the compromised account.
Recommendations
For Dell EMC Data Protection Search versions 19.4 and prior, update to a version later than 19.4 to resolve the issue.
For IDPA versions 2.6.1 and prior, update to a version later than 2.6.1 to resolve the issue.
As a temporary workaround, consider restricting access to the log files to minimize the risk of exploitation.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Data Protection Search
Idpa