Vulnerability Description
EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local users to obtain sensitive information by reading the management-server configuration file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emc | Geosynchrony | <= 5.2 |
| Emc | Vplex Geo | - |
| Emc | Vplex Local | - |
| Emc | Vplex Metro | - |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2013-09/0135.html
- http://archives.neohapsis.com/archives/bugtraq/2013-09/0135.html
FAQ
What is CVE-2013-3278?
CVE-2013-3278 is a vulnerability with a CVSS score of 4.9 (MEDIUM). EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local users to obtain sensitive information by reading the management-server configura...
How severe is CVE-2013-3278?
CVE-2013-3278 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3278?
Check the references section above for vendor advisories and patch information. Affected products include: Emc Geosynchrony, Emc Vplex Geo, Emc Vplex Local, Emc Vplex Metro.