First published: Wed Apr 16 2025(Updated: )
Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas Data Insight | <7.1.2 | |
Dell EMC Isilon OneFS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-43704 has been classified as a critical vulnerability due to the exposure of cleartext credentials.
To fix CVE-2025-43704, upgrade Veritas Data Insight to version 7.1.2 or later.
CVE-2025-43704 affects versions of Arctera Veritas Data Insight before 7.1.2 when configured with HTTP Basic Authentication.
The risks associated with CVE-2025-43704 include unauthorized access to sensitive information due to exposure of cleartext credentials.
Yes, CVE-2025-43704 is specifically relevant when Veritas Data Insight interacts with Dell Isilon OneFS servers.