First published: Tue Oct 01 2013(Updated: )
EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local users to obtain sensitive information by reading the management-server configuration file.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC GeoSynchrony | <=5.2 | |
Dell EMC VPLEX GeoSynchrony | ||
Dell EMC VPLEX | ||
EMC VPLEX Metro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3278 is considered a high-severity vulnerability due to the exposure of sensitive information via cleartext storage of LDAP/AD bind passwords.
To fix CVE-2013-3278, upgrade to VPLEX GeoSynchrony 5.2 SP1 or a later version that resolves this issue.
CVE-2013-3278 affects users of EMC VPLEX systems running versions of GeoSynchrony prior to 5.2 SP1.
CVE-2013-3278 allows local users to access sensitive LDAP/AD bind passwords stored in cleartext in the management-server configuration file.
There is no officially documented workaround for CVE-2013-3278; the recommended action is to upgrade the affected software.