Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products

DSA-2021-306: Dell EMC Enterprise Storage Analytics for vRealize Operations Security Update Credential Disclosure Vulnerability

Summary: Dell EMC Enterprise Storage Analytics for vRealize Operations remediation is available for the vulnerability that may be exploited by a local high privileged malicious user to expose certain user credentials. Dell recommends implementing this remediation as soon as possible. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

Component CVEs More information
Dell EMC Enterprise Storage Analytics for vRealize Operations CVE-2021-43590 Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. 
Component CVEs More information
Dell EMC Enterprise Storage Analytics for vRealize Operations CVE-2021-43590 Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. 
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Versions Updated Versions Link to Update
Dell EMC Enterprise Storage Analytics for vRealize Operations Versions before 6.1.0 Upgrade ESA to 6.3.0 or later, and vROps to latest https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview
Dell EMC Enterprise Storage Analytics for vRealize Operations Versions 6.1.x and 6.2.x Upgrade ESA to 6.3.0 or later https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview
Product Affected Versions Updated Versions Link to Update
Dell EMC Enterprise Storage Analytics for vRealize Operations Versions before 6.1.0 Upgrade ESA to 6.3.0 or later, and vROps to latest https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview
Dell EMC Enterprise Storage Analytics for vRealize Operations Versions 6.1.x and 6.2.x Upgrade ESA to 6.3.0 or later https://www.dell.com/support/home/en-us/product-support/product/storage-analytics/overview

Revision History

RevisionDateDescription
1.02022-02-14Initial Release

Related Information

Affected Products

Enterprise Storage Analytics for vRealize Operations

Products

Product Security Information
Article Properties
Article Number: 000196329
Article Type: Dell Security Advisory
Last Modified: 14 Feb 2022
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.