Home
HIGH: 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:HDefault status
unaffected
Any version before x.40.405
affected
Description
Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A local high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable component with privileges of the compromised account.
Problem types
CWE-256: Plaintext Storage of a Password
Product status
Any version before x.40.405
References
www.dell.com/...l-plaintext-password-storage-vulnerabilities