Lucene search

K
cve[email protected]CVE-2015-0514
HistoryJan 21, 2015 - 3:17 p.m.

CVE-2015-0514

2015-01-2115:17:12
CWE-200
web.nvd.nist.gov
26
emc
m&r
watch4net
vipr srm
cve-2015-0514
cleartext
data-center discovery
remote attackers
srm access
decryption attack

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.082 Low

EPSS

Percentile

94.4%

EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack.

Affected configurations

NVD
Node
emcwatch4netRange6.5
Node
emcvipr_srmRange3.6.0
CPENameOperatorVersion
emc:watch4netemc watch4netle6.5

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.082 Low

EPSS

Percentile

94.4%