PT-2021-23601 · Xorux · Lpar2Rrd+1

Simon Geusebroek

·

Published

2021-11-08

·

Updated

2022-09-03

·

CVE-2021-42371

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LPAR2RRD and STOR2RRD versions prior to 7.30
Description The issue concerns a hardcoded system account named lpar2rrd in XoruX LPAR2RRD and STOR2RRD.
Recommendations For versions prior to 7.30, update to version 7.30 or later to resolve the issue.

Fix

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2021-42371
GHSA-P2FQ-9H5J-X6W5

Affected Products

Lpar2Rrd
Stor2Rrd