First published: Mon Apr 19 2021(Updated: )
Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability when the Dell Upgrade Readiness Utility is run on the system. The credentials of the Unisphere Administrator are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Unity Operating Environment | <5.0.7.0.5.008 | |
Dell Unity Xt Operating Environment | <5.0.7.0.5.008 | |
Dell Unityvsa Operating Environment | <5.0.7.0.5.008 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-21547.
The severity of CVE-2021-21547 is medium with a CVSS score of 6.7.
Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 are affected by CVE-2021-21547.
A local malicious user with high privilege can exploit the plain-text password storage vulnerability.
To fix CVE-2021-21547, update Dell EMC Unity, UnityVSA, and Unity XT to version 5.0.7.0.5.008 or higher.