HIGH🇵🇱 Wersja polska

CVE-2021-21601

CVSS 8.8v3.1pub. 2021-08-10upd. 2024-11-21

Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CIS. A local low privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with the privileges of the compromised account.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Dell Emc Data Protection Search

    APP
    Dell
    < 19.5
  • Dell Emc Integrated Data Protection Appliance

    APP
    Dell
    < 2.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-29495CRITICAL10.0PL ✓same product

RCE bez uwierzytelnienia w Dell EMC Avamar Server — command injection

CVE-2020-29493CRITICAL10.0PL ✓same product

SQL Injection w Dell EMC Avamar Server — nieautoryzowany dostęp do danych

CVE-2018-11066CRITICAL9.8PL ✓same product

RCE w Dell EMC Avamar Client Manager — zdalny dostęp bez uwierzytelnienia

CVE-2018-1217CRITICAL9.8PL ✓same product

Brak kontroli dostępu w Dell EMC Avamar Installation Manager — ujawnienie danych uwierzytelniających

CVE-2019-3752HIGH8.2same product

Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection App...