Article Number: 000196329
Medium
Component | CVEs | More information |
Dell EMC Enterprise Storage Analytics for vRealize Operations | CVE-2021-43590 | Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. |
Component | CVEs | More information |
Dell EMC Enterprise Storage Analytics for vRealize Operations | CVE-2021-43590 | Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. |
Product | Affected Versions | Updated Versions | Link to Update |
Dell EMC Enterprise Storage Analytics for vRealize Operations | Versions before 6.1.0 | Upgrade ESA to 6.3.0 or later, and vROps to latest | https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview |
Dell EMC Enterprise Storage Analytics for vRealize Operations | Versions 6.1.x and 6.2.x | Upgrade ESA to 6.3.0 or later | https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview |
Product | Affected Versions | Updated Versions | Link to Update |
Dell EMC Enterprise Storage Analytics for vRealize Operations | Versions before 6.1.0 | Upgrade ESA to 6.3.0 or later, and vROps to latest | https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview |
Dell EMC Enterprise Storage Analytics for vRealize Operations | Versions 6.1.x and 6.2.x | Upgrade ESA to 6.3.0 or later | https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview |
Revision | Date | Description |
1.0 | 2022-02-14 | Initial Release |
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide
Enterprise Storage Analytics for vRealize Operations
Product Security Information
14 Feb 2022
1
Dell Security Advisory