First published: Tue May 29 2018(Updated: )
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password to use it in further attacks.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RecoverPoint | <5.1.2 | |
Dell RecoverPoint for Virtual Machines | <5.1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1241.
The severity level of CVE-2018-1241 is high.
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3 are affected by CVE-2018-1241.
An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password.
Yes, you can find references for CVE-2018-1241 at the following links: [Reference 1](http://seclists.org/fulldisclosure/2018/May/61), [Reference 2](http://www.securityfocus.com/bid/104246).