First published: Thu Oct 18 2018(Updated: )
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed password to gain access to the application database.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Secure Remote Services | <3.32.00.08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11079 is a vulnerability in Dell EMC Secure Remote Services versions prior to 3.32.00.08 that allows an authenticated malicious user to obtain exposed passwords stored in plaintext.
CVE-2018-11079 affects Dell EMC Secure Remote Services versions prior to 3.32.00.08 by storing database credentials in plaintext in a configuration file, making them accessible to authenticated malicious users.
CVE-2018-11079 has a severity rating of 7.8 (high).
An authenticated malicious user with access to the configuration file can exploit CVE-2018-11079 by obtaining the exposed plaintext password, thereby gaining unauthorized access.
To fix CVE-2018-11079, upgrade Dell EMC Secure Remote Services to version 3.32.00.08 or later, which addresses the plaintext password storage vulnerability.