CVE-2013-3272: Low severity emc replication manager vulnerability
Published Jul 8, 2013
·Updated
EMC Replication Manager (RM) before 5.4.4 places encoded passwords in application log files, which makes it easier for local users to obtain sensitive information by reading a file and conducting an unspecified decoding attack.
Affected Software
1 affected component
EMC Replication Manager<=5.4.3
Event History
Jul 8, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3272?
The severity of CVE-2013-3272 is considered medium due to the risk of sensitive information disclosure.
2
How do I fix CVE-2013-3272?
To fix CVE-2013-3272, upgrade EMC Replication Manager to version 5.4.4 or later.
3
What type of vulnerabilities does CVE-2013-3272 involve?
CVE-2013-3272 involves sensitive information disclosure due to improper password handling in log files.
4
Who is affected by CVE-2013-3272?
Users of EMC Replication Manager versions prior to 5.4.4 are affected by CVE-2013-3272.
5
What can attackers do with CVE-2013-3272?
Attackers with local access can potentially decode encoded passwords from application log files as a result of CVE-2013-3272.