CVE-2020-29489: Medium severity Dell EMC Unity Operating Environment vulnerability
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in a system file. A local authenticated attacker with access to the system files may use the exposed password to gain access with the privileges of the compromised user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-29489?
CVE-2020-29489 has a moderate severity due to the risks associated with plain-text password storage that can be exploited by local authenticated attackers.
How do I fix CVE-2020-29489?
To fix CVE-2020-29489, upgrade to Dell EMC Unity, Unity XT, or UnityVSA versions 5.0.4.0.5.012 or later.
What are the implications of CVE-2020-29489?
The implications of CVE-2020-29489 include potential unauthorized access to sensitive user credentials, which may lead to further system compromise.
Which software versions are affected by CVE-2020-29489?
CVE-2020-29489 affects Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012.
Who can exploit CVE-2020-29489?
CVE-2020-29489 can be exploited by local authenticated attackers with access to the affected Dell EMC systems.