CVE-2014-4620

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
25/10/2014
Last modified:
12/04/2025

Description

The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:meditech:meditech:3.0:87:*:*:*:*:*:*
cpe:2.3:a:meditech:meditech:3.0:90:*:*:*:*:*:*
cpe:2.3:a:emc:networker:*:*:*:*:*:*:*:*