Vulnerability CVE-2013-3278


Published: 2013-09-30   Modified: 2013-10-04

Description:
EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local users to obtain sensitive information by reading the management-server configuration file.

See advisories in our WLB2 database:
Topic
Author
Date
Low
EMC VPLEX Information Disclosure
ESA
27.09.2013

Type:

CWE-255

(Credentials Management)

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.9/10
6.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None
Affected software
EMC -> Geosynchrony 
EMC -> Vplex geo 
EMC -> Vplex local 
EMC -> Vplex metro 

 References:
http://archives.neohapsis.com/archives/bugtraq/2013-09/0135.html

Copyright 2024, cxsecurity.com

 

Back to Top