First published: Wed Nov 18 2015(Updated: )
The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log file, which allows local users to obtain sensitive information by reading this file.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC VPLEX GeoSynchrony | =5.4-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6847 is classified as a medium severity vulnerability due to its impact on sensitive information exposure.
To mitigate CVE-2015-6847, upgrade EMC VPLEX GeoSynchrony to a version that does not store passwords in cleartext within log files.
CVE-2015-6847 affects users of EMC VPLEX GeoSynchrony version 5.4 SP1 before P3 who have the default configuration.
CVE-2015-6847 exposes cleartext NAVISPHERE GUI passwords in log files, making them accessible to local users.
CVE-2015-6847 presents a local attack vector since it requires local access to the log files to exploit the vulnerability.