Vulnerability CVE-2014-4620


Published: 2014-10-25

Description:
The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Meditech -> Meditech 
EMC -> Networker 

 References:
http://xforce.iss.net/xforce/xfdb/97756
http://www.securitytracker.com/id/1031116
http://www.securityfocus.com/bid/70726
http://packetstormsecurity.com/files/128841/EMC-NetWorker-Module-For-MEDITECH-NMMEDI-Information-Disclosure.html
http://archives.neohapsis.com/archives/bugtraq/2014-10/0145.html

Copyright 2024, cxsecurity.com

 

Back to Top