CVE-2021-21590

EUVD-2021-8862
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 MEDIUM
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
dellCNA
6.4 MEDIUM
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
dellemc_unity_operating_environment
𝑥
< 5.1.0.0.5.394
dellemc_unity_xt_operating_environment
𝑥
< 5.1.0.0.5.394
dellemc_unityvsa_operating_environment
𝑥
< 5.1.0.0.5.394
𝑥
= Vulnerable software versions