First published: Thu Feb 25 2021(Updated: )
Dell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vulnerability. A local low-privileged user of the Networker server could potentially exploit this vulnerability to read plain-text credentials from server log files.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC NetWorker | >=19.1.1.0<19.3.0.4 | |
Dell EMC NetWorker | =18.1.0.1 | |
Dell EMC NetWorker | =18.1.0.2 | |
Dell EMC NetWorker | =18.2.0.0 | |
Dell EMC NetWorker | =19.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21546 has been rated as a medium severity vulnerability due to its potential for information disclosure.
To fix CVE-2021-21546, upgrade Dell EMC NetWorker to version 19.3.0.4 or 19.4.0.1 or later.
CVE-2021-21546 could allow low-privileged users to read plain-text credentials stored in server log files.
CVE-2021-21546 affects Dell EMC NetWorker versions 18.x and 19.x prior to 19.3.0.4 and 19.4.0.0.
Low-privileged users with access to the Networker server are at risk of exploiting CVE-2021-21546.