CVE-2019-18576
Summary
| CVE | CVE-2019-18576 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-13 21:15:00 UTC |
| Updated | 2020-03-18 16:09:00 UTC |
| Description | Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Malicious local users with access to the log files may use the exposed passwords to gain access to XtremIO with the privileges of the compromised user. |
Risk And Classification
Problem Types: CWE-532
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dell | Xtremio Management Server | All | All | All | All |
| Application | Dell | Xtremio Management Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DSA-2019-172: Dell EMC XtremIO Security Update for Multiple Vulnerabilities | Dell US | MISC | www.dell.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.