{"api_version":"1","generated_at":"2026-07-23T14:00:22+00:00","cve":"CVE-2021-43590","urls":{"html":"https://cve.report/CVE-2021-43590","api":"https://cve.report/api/cve/CVE-2021-43590.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-43590","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-43590"},"summary":{"title":"CVE-2021-43590","description":"Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.","state":"PUBLIC","assigner":"secure@dell.com","published_at":"2022-03-04 21:15:00","updated_at":"2022-03-12 02:05:00"},"problem_types":["CWE-312"],"metrics":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000196329/dsa-2021","name":"https://www.dell.com/support/kbdoc/en-us/000196329/dsa-2021","refsource":"MISC","tags":[],"title":"Access Denied","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-43590","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43590","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"43590","vulnerable":"1","versionEndIncluding":"6.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dell","cpe5":"enterprise_storage_analytics","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"vrealize_operations","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secure@dell.com","DATE_PUBLIC":"2022-02-14","ID":"CVE-2021-43590","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Dell EMC Enterprise Storage Analytics for vRealize Operations","version":{"version_data":[{"version_affected":"<","version_value":"6.2.1"}]}}]},"vendor_name":"Dell"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account."}]},"impact":{"cvss":{"baseScore":6,"baseSeverity":"Medium","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-256: Unprotected Storage of Credentials"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.dell.com/support/kbdoc/en-us/000196329/dsa-2021","name":"https://www.dell.com/support/kbdoc/en-us/000196329/dsa-2021"}]}},"nvd":{"publishedDate":"2022-03-04 21:15:00","lastModifiedDate":"2022-03-12 02:05:00","problem_types":["CWE-312"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6,"baseSeverity":"MEDIUM"},"exploitabilityScore":0.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.6},"severity":"LOW","exploitabilityScore":3.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:dell:enterprise_storage_analytics:*:*:*:*:*:vrealize_operations:*:*","versionStartIncluding":"4.0.1","versionEndIncluding":"6.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"43590","Ordinal":"220683","Title":"CVE-2021-43590","CVE":"CVE-2021-43590","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"43590","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}