PT-2022-19404 · Dell · Dell Unity+2
Published
2022-06-02
·
Updated
2022-06-13
·
CVE-2022-29085
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173
Description
The issue concerns a plain-text password storage vulnerability that occurs when certain off-array tools are run on the system. This vulnerability exposes the credentials of a user with high privileges, storing them in plain text. A local malicious user with high privileges may exploit this to gain access with the privileges of the compromised user.
Recommendations
For Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173, update to version 5.2.0.0.5.173 or later to resolve the issue. As a temporary workaround, consider restricting access to off-array tools that may trigger the vulnerability until a patch is applied.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Unity
Dell Unity Xt
Dell Unityvsa