CVE-2019-3741: High severity Dell EMC Unity Operating Environment vulnerability
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user’s (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the Data Collection bundle may use the exposed password to gain access with the privileges of the compromised user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3741?
The severity of CVE-2019-3741 is high.
What software versions are affected by CVE-2019-3741?
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 are affected by CVE-2019-3741.
How does CVE-2019-3741 exploit work?
CVE-2019-3741 exploits the plain-text password storage vulnerability in Dell EMC Unity and UnityVSA.
What is the CWE category of CVE-2019-3741?
The CWE category of CVE-2019-3741 is CWE-693 (Protection Mechanism Failure).
How can I fix CVE-2019-3741?
To fix CVE-2019-3741, update Dell EMC Unity and UnityVSA to version 5.0.0.0.5.116 or later.