CVE-2021-21590: Infoleak
Published Jul 12, 2021
·Updated
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.
Affected Software
3 affected components
Dell EMC Unity Operating Environment<5.1.0.0.5.394
Dell Emc Unity Xt Operating Environment<5.1.0.0.5.394
Dell Emc Unityvsa Operating Environment<5.1.0.0.5.394
Event History
Jul 12, 2021
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Dell EMC Unity vulnerability?
The vulnerability ID is CVE-2021-21590.
2
What is the severity of CVE-2021-21590?
The severity of CVE-2021-21590 is medium.
3
Which software versions are affected by CVE-2021-21590?
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 are affected.
4
What is the impact of exploiting this vulnerability?
A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.
5
How can I fix CVE-2021-21590?
Update Dell EMC Unity, Unity XT, and UnityVSA to version 5.1.0.0.5.394 or later to fix the vulnerability.