CVE-2025-43704: Medium severity veritas data insight vulnerability
Published Apr 16, 2025
·Updated
Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.
Affected Software
2 affected components
Arctera Veritas Data Insight<7.1.2
Dell Isilon OneFS
Event History
Apr 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Apr 17, 57340
Event
via FIRST·01:40 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-43704?
CVE-2025-43704 has been classified as a critical vulnerability due to the exposure of cleartext credentials.
2
How do I fix CVE-2025-43704?
To fix CVE-2025-43704, upgrade Veritas Data Insight to version 7.1.2 or later.
3
What systems are affected by CVE-2025-43704?
CVE-2025-43704 affects versions of Arctera Veritas Data Insight before 7.1.2 when configured with HTTP Basic Authentication.
4
What are the risks associated with CVE-2025-43704?
The risks associated with CVE-2025-43704 include unauthorized access to sensitive information due to exposure of cleartext credentials.
5
Is CVE-2025-43704 related to Dell Isilon OneFS?
Yes, CVE-2025-43704 is specifically relevant when Veritas Data Insight interacts with Dell Isilon OneFS servers.