First published: Sat Nov 02 2013(Updated: )
The NetWorker Management Console (NMC) in EMC NetWorker 8.0.x before 8.0.2.3, when using Active Directory/LDAP for authentication, allows remote authenticated users to discover cleartext administrator passwords via (1) unspecified NMC audit reports or (2) requests to RAP resources.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetWorker | =8.0 | |
NetWorker | =8.0.0.1 | |
NetWorker | =8.0.0.2 | |
NetWorker | =8.0.0.3 | |
NetWorker | =8.0.0.4 | |
NetWorker | =8.0.0.5 | |
NetWorker | =8.0.0.6 | |
NetWorker | =8.0.1.3 | |
NetWorker | =8.0.1.4 | |
NetWorker | =8.0.1.5 | |
NetWorker | =8.0.1.6 | |
NetWorker | =8.0.2.0 | |
NetWorker | =8.0.2.1 | |
NetWorker | =8.0.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3285 has a severity rating of high due to the potential for remote authenticated users to access cleartext administrator passwords.
To fix CVE-2013-3285, upgrade EMC NetWorker to version 8.0.2.3 or later.
CVE-2013-3285 affects users of EMC NetWorker versions 8.0.x before 8.0.2.3 that utilize Active Directory/LDAP for authentication.
CVE-2013-3285 can expose cleartext administrator passwords through specific NMC audit reports or requests to RAP resources.
CVE-2013-3285 is a remote vulnerability, allowing authenticated users to exploit the flaw from a remote location.