CVE-2021-21591: Infoleak
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21591?
CVE-2021-21591 is a vulnerability in Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 that allows a local malicious user with high privileges to access the system with the compromised user's privileges.
What is the severity of CVE-2021-21591?
The severity of CVE-2021-21591 is medium with a CVSS score of 6.7.
How does CVE-2021-21591 affect Dell EMC Unity?
CVE-2021-21591 affects Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 by exposing plain-text passwords and allowing local malicious users to gain unauthorized access.
How can I fix CVE-2021-21591?
To fix CVE-2021-21591, it is recommended to update Dell EMC Unity, Unity XT, and UnityVSA to version 5.1.0.0.5.394 or later, which resolves the plain-text password storage vulnerability.
Where can I find more information about CVE-2021-21591?
More information about CVE-2021-21591 can be found on the Dell support knowledge base at https://www.dell.com/support/kbdoc/000189204.