CVE-2013-3287: Low severity emc unisphere vulnerability
Published Nov 2, 2013
·Updated
EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cleartext LDAP bind password by reading the console.
Affected Software
4 affected components
Dell Emc Unisphere Vmax<=1.6
Dell Emc Unisphere Vmax=1.0
Dell Emc Unisphere Vmax=1.1
Dell Emc Unisphere Vmax=1.5
Event History
Nov 2, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3287?
CVE-2013-3287 has a medium severity rating due to the potential exposure of sensitive LDAP credentials.
2
How do I fix CVE-2013-3287?
To fix CVE-2013-3287, update your EMC Unisphere for VMAX to version 1.6.1.6 or higher to secure the LDAP configurations.
3
Who is affected by CVE-2013-3287?
Users of EMC Unisphere for VMAX versions prior to 1.6.1.6 are affected by CVE-2013-3287.
4
What type of vulnerability is CVE-2013-3287?
CVE-2013-3287 is a local information disclosure vulnerability related to unknowingly logging debug information.
5
How can local users exploit CVE-2013-3287?
Local users can exploit CVE-2013-3287 by reading console logs that reveal the cleartext LDAP bind password.