QID 375579
Date Published: 2021-08-31
QID 375579: Dell EMC NetWorker Multiple Vulnerabilites (DSA-2021-104)
Dell EMC NetWorker is a suite of enterprise level data protection software that unifies and automates backup to tape, disk-based, and flash-based storage media across physical and virtual environments for granular and disaster recovery.
CVE-2021-21558: A local administrator of the gstd system may potentially exploit this vulnerability to read LDAP credentials from local logs.
CVE-2021-21559: An unauthenticated attacker in the same network collision domain as the NetWorker Management Console client could potentially exploit this vulnerability to perform man-in-the-middle attacks.
Affected Versions:
Dell EMC NetWorker 18.x
Dell EMC NetWorker 19.1.x
Dell EMC NetWorker 19.2.x
Dell EMC NetWorker 19.3.x
Dell EMC NetWorker 19.4 and 19.4.0.1
QID Detection Logic (Authenticated):
This QID check Windows registry to see if vulnerable version of Dell EMC NetWorker is installed.
Successful exploitation of these vulnerabilities may allow an attacker either steal sensitive information or perform man-in-the-middle attacks.
CVEs related to QID 375579
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| DSA-2021-104 |
|