First published: Sat Oct 25 2014(Updated: )
The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Meditech Meditech | =3.0-87 | |
Meditech Meditech | =3.0-90 | |
NetWorker |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4620 is classified as a moderate severity vulnerability due to the risk of sensitive information exposure.
To fix CVE-2014-4620, it is recommended to upgrade to a version of the EMC NetWorker Module for MEDITECH that does not store credentials in cleartext.
CVE-2014-4620 exposes cleartext RecoverPoint Appliance credentials, which are sensitive information.
CVE-2014-4620 affects users of EMC NetWorker Module for MEDITECH version 3.0 builds 87 through 90.
Yes, local users can exploit CVE-2014-4620 by accessing the nsrmedisv.raw log files to obtain sensitive credentials.