CVE-2013-3285: Low severity networker vulnerability
The NetWorker Management Console (NMC) in EMC NetWorker 8.0.x before 8.0.2.3, when using Active Directory/LDAP for authentication, allows remote authenticated users to discover cleartext administrator passwords via (1) unspecified NMC audit reports or (2) requests to RAP resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3285?
CVE-2013-3285 has a severity rating of high due to the potential for remote authenticated users to access cleartext administrator passwords.
How do I fix CVE-2013-3285?
To fix CVE-2013-3285, upgrade EMC NetWorker to version 8.0.2.3 or later.
Who is affected by CVE-2013-3285?
CVE-2013-3285 affects users of EMC NetWorker versions 8.0.x before 8.0.2.3 that utilize Active Directory/LDAP for authentication.
What types of data can be exposed due to CVE-2013-3285?
CVE-2013-3285 can expose cleartext administrator passwords through specific NMC audit reports or requests to RAP resources.
Is CVE-2013-3285 a local or remote vulnerability?
CVE-2013-3285 is a remote vulnerability, allowing authenticated users to exploit the flaw from a remote location.