CVE-2021-21546

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
29/07/2021
Last modified:
05/08/2021

Description

Dell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vulnerability. A local low-privileged user of the Networker server could potentially exploit this vulnerability to read plain-text credentials from server log files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:emc_networker:*:*:*:*:*:*:*:* 19.1.1.0 (including) 19.3.0.4 (excluding)
cpe:2.3:a:dell:emc_networker:18.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:dell:emc_networker:18.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:dell:emc_networker:18.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:emc_networker:19.4.0.0:*:*:*:*:*:*:*