CVE-2014-4620
Summary
| CVE | CVE-2014-4620 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-25 10:55:00 UTC |
| Updated | 2017-08-29 01:35:00 UTC |
| Description | The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Networker | All | All | All | All |
| Application | Emc | Networker | All | All | All | All |
| Application | Meditech | Meditech | 3.0 | 87 | All | All |
| Application | Meditech | Meditech | 3.0 | 90 | All | All |
| Application | Meditech | Meditech | 3.0 | 87 | All | All |
| Application | Meditech | Meditech | 3.0 | 90 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EMC NetWorker Module for MEDITECH Password Disclosure Flaw Lets Local Users Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | |
| EMC NetWorker Module for MEDITECH CVE-2014-4620 Local Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| 20141022 ESA-2014-087: EMC NetWorker Module for MEDITECH (NMMEDI) Information Disclosure Vulnerability | BUGTRAQ | archives.neohapsis.com | |
| EMC NetWorker Module For MEDITECH (NMMEDI) Information Disclosure ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Security Advisory SA61952 - EMC NetWorker Module for Meditech Credentials Logging Security Issue - Secunia | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.