CVE-2020-26199: Medium severity Dell EMC Unity Operating Environment vulnerability
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple log files. A local authenticated attacker with access to the log files may use the exposed password to gain access with the privileges of the compromised user.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Dell EMC Unity vulnerability?
The vulnerability ID for this Dell EMC Unity vulnerability is CVE-2020-26199.
What is the severity of CVE-2020-26199?
CVE-2020-26199 has a severity rating of 6.7 (Medium).
What is affected by CVE-2020-26199?
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 are affected by CVE-2020-26199.
How does CVE-2020-26199 impact security?
CVE-2020-26199 exposes user credentials, including the Unisphere admin privilege user password, in plain text in multiple log files.
Is there a fix available for CVE-2020-26199?
Yes, Dell has released a fix for CVE-2020-26199. It is recommended to upgrade to Unity, Unity XT, and UnityVSA versions 5.0.4.0.5.012 or later.