Lucene search

K
cveDellCVE-2014-4620
HistoryOct 25, 2014 - 10:55 a.m.

CVE-2014-4620

2014-10-2510:55:06
CWE-200
dell
web.nvd.nist.gov
23
emc
networker
meditech
nmmedi
cve-2014-4620
security
credential storage
sensitive information disclosure

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0

Percentile

5.1%

The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files.

Affected configurations

Nvd
Node
meditechmeditechMatch3.087
OR
meditechmeditechMatch3.090
Node
emcnetworker
VendorProductVersionCPE
meditechmeditech3.0cpe:2.3:a:meditech:meditech:3.0:87:*:*:*:*:*:*
meditechmeditech3.0cpe:2.3:a:meditech:meditech:3.0:90:*:*:*:*:*:*
emcnetworker*cpe:2.3:a:emc:networker:*:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0

Percentile

5.1%