CVE-2018-11079: High severity dell emc secure remote services vulnerability
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed password to gain access to the application database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11079?
CVE-2018-11079 is a vulnerability in Dell EMC Secure Remote Services versions prior to 3.32.00.08 that allows an authenticated malicious user to obtain exposed passwords stored in plaintext.
How does CVE-2018-11079 affect Dell EMC Secure Remote Services?
CVE-2018-11079 affects Dell EMC Secure Remote Services versions prior to 3.32.00.08 by storing database credentials in plaintext in a configuration file, making them accessible to authenticated malicious users.
What is the severity rating of CVE-2018-11079?
CVE-2018-11079 has a severity rating of 7.8 (high).
How can an authenticated malicious user exploit CVE-2018-11079?
An authenticated malicious user with access to the configuration file can exploit CVE-2018-11079 by obtaining the exposed plaintext password, thereby gaining unauthorized access.
How can I fix CVE-2018-11079?
To fix CVE-2018-11079, upgrade Dell EMC Secure Remote Services to version 3.32.00.08 or later, which addresses the plaintext password storage vulnerability.