8.8
CVE-2018-1241
- EPSS 0.81%
- Veröffentlicht 29.05.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:26
- Quelle security_alert@emc.com
- Teams Watchlist Login
- Unerledigt Login
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password to use it in further attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emc ≫ Recoverpoint Version < 5.1.2
Emc ≫ Recoverpoint For Virtual Machines Version < 5.1.1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.81% | 0.729 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.