CVE-2019-3741 vulnerability in Dell Products
Published on July 18, 2019
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere users (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the Data Collection bundle may use the exposed password to gain access with the privileges of the compromised user.
Products Associated with CVE-2019-3741
stack.watch emails you whenever new vulnerabilities are published in Dell Emc Unityvsa Operating Environment or Dell Emc Unity Operating Environment. Just hit a watch button to start following.
Affected Versions
DELL EMC Unity:- Version 5.0 and below 5.0.0.0.5.116 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.