First published: Wed Jan 21 2015(Updated: )
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Watch4Net | <=6.5 | |
Dell EMC ViPR SRM | <=3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-0514 is classified as high due to the potential exposure of sensitive credentials.
To fix CVE-2015-0514, you should upgrade to EMC M&R version 6.5u1 or ViPR SRM version 3.6.1 or later.
CVE-2015-0514 affects EMC M&R versions prior to 6.5u1 and ViPR SRM versions prior to 3.6.1.
CVE-2015-0514 can be exploited by remote attackers to perform a decryption attack on cleartext data-center discovery credentials.
CVE-2015-0514 is considered a remote vulnerability as it can be exploited by attackers from outside the affected systems.