CVE-2021-21546: High severity Dell EMC NetWorker vulnerability
Dell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vulnerability. A local low-privileged user of the Networker server could potentially exploit this vulnerability to read plain-text credentials from server log files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21546?
CVE-2021-21546 has been rated as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2021-21546?
To fix CVE-2021-21546, upgrade Dell EMC NetWorker to version 19.3.0.4 or 19.4.0.1 or later.
What kind of information is disclosed in CVE-2021-21546?
CVE-2021-21546 could allow low-privileged users to read plain-text credentials stored in server log files.
Which versions of Dell EMC NetWorker are affected by CVE-2021-21546?
CVE-2021-21546 affects Dell EMC NetWorker versions 18.x and 19.x prior to 19.3.0.4 and 19.4.0.0.
Who is at risk from CVE-2021-21546?
Low-privileged users with access to the Networker server are at risk of exploiting CVE-2021-21546.