First published: Fri Mar 15 2002(Updated: )
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWorker | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0114 is considered a high severity vulnerability due to the risk of local privilege escalation.
To mitigate CVE-2002-0114, upgrade EMC NetWorker to a version higher than 7.0 that does not store passwords in plaintext.
CVE-2002-0114 affects users of EMC NetWorker version 6.1 running on the Solaris 7 platform.
CVE-2002-0114 is a local privilege escalation vulnerability linked to insecure password storage.
CVE-2002-0114 cannot be exploited remotely as it requires local access to the system.