Dell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A local administrator of the gstd system may potentially exploit this vulnerability to read LDAP credentials from local logs and use the stolen credentials to make changes to the network domain.
References
Link | Resource |
---|---|
https://www.dell.com/support/kbdoc/en-us/000186638/dsa-2021-104-dell-emc-networker-security-update-for-multiple-vulnerabilities | Patch Vendor Advisory |
Configurations
History
16 Jun 2021, 00:29
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://www.dell.com/support/kbdoc/en-us/000186638/dsa-2021-104-dell-emc-networker-security-update-for-multiple-vulnerabilities - Patch, Vendor Advisory | |
CPE | cpe:2.3:a:dell:emc_networker:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 2.1
v3 : 4.4 |
CWE | CWE-532 |
08 Jun 2021, 18:58
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-06-08 18:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-21558
Mitre link : CVE-2021-21558
CVE.ORG link : CVE-2021-21558
JSON object : View
Products Affected
dell
- emc_networker
CWE
CWE-532
Insertion of Sensitive Information into Log File