PT-2022-19404 · Dell · Dell Unity+2

Published

2022-06-02

·

Updated

2022-06-13

·

CVE-2022-29085

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173
Description The issue concerns a plain-text password storage vulnerability that occurs when certain off-array tools are run on the system. This vulnerability exposes the credentials of a user with high privileges, storing them in plain text. A local malicious user with high privileges may exploit this to gain access with the privileges of the compromised user.
Recommendations For Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173, update to version 5.2.0.0.5.173 or later to resolve the issue. As a temporary workaround, consider restricting access to off-array tools that may trigger the vulnerability until a patch is applied.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29085

Affected Products

Dell Unity
Dell Unity Xt
Dell Unityvsa