#VU79010 Insufficiently protected credentials in Dell products - CVE-2022-29085
Published: August 7, 2023
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell
Description
The vulnerability allows a local privileged user to execute arbitrary code on the target system.
The vulnerability exists due to Dell Unity, Dell UnityVSA, and Dell Unity XT contain a plain-text password storage vulnerability when certain off-array tools are run on the system. A local privileged user can use the exposed password to gain access with the privileges of the compromised user.