First published: Mon Jul 12 2021(Updated: )
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Unity Operating Environment | <5.1.0.0.5.394 | |
Dell Emc Unity Xt Operating Environment | <5.1.0.0.5.394 | |
Dell Emc Unityvsa Operating Environment | <5.1.0.0.5.394 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21591 is a vulnerability in Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 that allows a local malicious user with high privileges to access the system with the compromised user's privileges.
The severity of CVE-2021-21591 is medium with a CVSS score of 6.7.
CVE-2021-21591 affects Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 by exposing plain-text passwords and allowing local malicious users to gain unauthorized access.
To fix CVE-2021-21591, it is recommended to update Dell EMC Unity, Unity XT, and UnityVSA to version 5.1.0.0.5.394 or later, which resolves the plain-text password storage vulnerability.
More information about CVE-2021-21591 can be found on the Dell support knowledge base at https://www.dell.com/support/kbdoc/000189204.