PT-2025-1065 · Dell · Dell Vxrail
Klaas Demter
·
Published
2025-01-08
·
Updated
2025-01-24
·
CVE-2025-21111
CVSS v3.1
7.5
High
| Vector | AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell VxRail versions 8.0.000 through 8.0.311
Description
The issue is related to the storage of critical information in plaintext, which could allow an attacker to expose protected information. A high-privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Recommendations
For Dell VxRail versions 8.0.000 through 8.0.311, consider disabling the storage of passwords in plaintext as a temporary workaround until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation. Update to a version that contains a fix for this vulnerability when available.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Vxrail