CVE-2014-4620
Summary
| CVE | CVE-2014-4620 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-25 10:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EMC NetWorker Module for MEDITECH Password Disclosure Flaw Lets Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| EMC NetWorker Module for MEDITECH CVE-2014-4620 Local Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| archives.neohapsis.com/archives/bugtraq/2014-10/0145.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| Security Advisory SA61952 - EMC NetWorker Module for Meditech Credentials Logging Security Issue - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| EMC NetWorker Module For MEDITECH (NMMEDI) Information Disclosure ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.