First published: Wed Nov 01 2017(Updated: )
EMC AppSync Server prior to 3.5.0.1 contains database accounts with hardcoded passwords that could potentially be exploited by malicious users to compromise the affected system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC AppSync | <3.5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14376 is classified as a high severity vulnerability due to the presence of hardcoded passwords that can be exploited.
To mitigate CVE-2017-14376, upgrade EMC AppSync to version 3.5.0.1 or later to eliminate the hardcoded passwords.
CVE-2017-14376 affects all versions of EMC AppSync prior to 3.5.0.1.
CVE-2017-14376 could enable unauthorized access and control over the EMC AppSync server due to compromised database accounts.
CVE-2017-14376 was reported by security researchers who identified the hardcoded passwords in EMC AppSync.