First published: Mon Aug 01 2011(Updated: )
EMC Data Protection Advisor before 5.8.1 places cleartext account credentials in the DPA configuration file in unspecified circumstances, which might allow local users to obtain sensitive information by reading this file.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Data Protection Advisor | <=5.8 | |
Dell EMC Data Protection Advisor | =5.0-sp1 | |
Dell EMC Data Protection Advisor | =5.6 | |
Dell EMC Data Protection Advisor | =5.6.1 | |
Dell EMC Data Protection Advisor | =5.7 | |
Dell EMC Data Protection Advisor | =5.7-sp1 | |
Dell EMC Data Protection Advisor | =5.7.1 | |
Dell EMC Data Protection Advisor | =5.8-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1742 has a medium severity rating due to the exposure of sensitive credentials.
To fix CVE-2011-1742, upgrade EMC Data Protection Advisor to version 5.8.1 or later.
CVE-2011-1742 allows local users to access account credentials stored in cleartext, potentially compromising security.
CVE-2011-1742 affects versions of EMC Data Protection Advisor prior to 5.8.1, including versions 5.0-sp1, 5.6, 5.6.1, 5.7, and 5.8-sp1.
There are no documented workarounds for CVE-2011-1742, so upgrading to a secure version is recommended.