Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000196329


DSA-2021-306: Dell EMC Enterprise Storage Analytics for vRealize Operations Security Update Credential Disclosure Vulnerability

Summary: Dell EMC Enterprise Storage Analytics for vRealize Operations remediation is available for the vulnerability that may be exploited by a local high privileged malicious user to expose certain user credentials. Dell recommends implementing this remediation as soon as possible. ...

Article Content


Impact

Medium

Details

Component CVEs More information
Dell EMC Enterprise Storage Analytics for vRealize Operations CVE-2021-43590 Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. 
Component CVEs More information
Dell EMC Enterprise Storage Analytics for vRealize Operations CVE-2021-43590 Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. 
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Affected Versions Updated Versions Link to Update
Dell EMC Enterprise Storage Analytics for vRealize Operations Versions before 6.1.0 Upgrade ESA to 6.3.0 or later, and vROps to latest https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview
Dell EMC Enterprise Storage Analytics for vRealize Operations Versions 6.1.x and 6.2.x Upgrade ESA to 6.3.0 or later https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview
Product Affected Versions Updated Versions Link to Update
Dell EMC Enterprise Storage Analytics for vRealize Operations Versions before 6.1.0 Upgrade ESA to 6.3.0 or later, and vROps to latest https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview
Dell EMC Enterprise Storage Analytics for vRealize Operations Versions 6.1.x and 6.2.x Upgrade ESA to 6.3.0 or later https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview

Revision History

RevisionDateDescription
1.02022-02-14Initial Release

Related Information


Article Properties


Affected Product

Enterprise Storage Analytics for vRealize Operations

Product

Product Security Information

Last Published Date

14 Feb 2022

Article Type

Dell Security Advisory