DSA-2021-306: Dell EMC Enterprise Storage Analytics for vRealize Operations Security Update Credential Disclosure Vulnerability
Summary: Dell EMC Enterprise Storage Analytics for vRealize Operations remediation is available for the vulnerability that may be exploited by a local high privileged malicious user to expose certain user credentials. Dell recommends implementing this remediation as soon as possible. ...
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Medium
Details
| Component | CVEs | More information |
| Dell EMC Enterprise Storage Analytics for vRealize Operations | CVE-2021-43590 | Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. |
| Component | CVEs | More information |
| Dell EMC Enterprise Storage Analytics for vRealize Operations | CVE-2021-43590 | Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. |
Affected Products & Remediation
| Product | Affected Versions | Updated Versions | Link to Update |
| Dell EMC Enterprise Storage Analytics for vRealize Operations | Versions before 6.1.0 | Upgrade ESA to 6.3.0 or later, and vROps to latest | https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview |
| Dell EMC Enterprise Storage Analytics for vRealize Operations | Versions 6.1.x and 6.2.x | Upgrade ESA to 6.3.0 or later | https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview |
| Product | Affected Versions | Updated Versions | Link to Update |
| Dell EMC Enterprise Storage Analytics for vRealize Operations | Versions before 6.1.0 | Upgrade ESA to 6.3.0 or later, and vROps to latest | https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview |
| Dell EMC Enterprise Storage Analytics for vRealize Operations | Versions 6.1.x and 6.2.x | Upgrade ESA to 6.3.0 or later | https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview |
Revision History
| Revision | Date | Description |
| 1.0 | 2022-02-14 | Initial Release |
Related Information
Legal Disclaimer
Affected Products
Enterprise Storage Analytics for vRealize OperationsProducts
Product Security InformationArticle Properties
Article Number: 000196329
Article Type: Dell Security Advisory
Last Modified: 18 Sep 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.