Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage.
The product writes sensitive information to a log file.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://www.dell.com/support/kbdoc/000193369 | patch vendor advisory |
https://security.gentoo.org/glsa/202210-09 | third party advisory vendor advisory |