Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-0645


EMC Cloud Tiering Appliance (CTA) 9.x through 10 SP1 and File Management Appliance (FMA) 7.x store DES password hashes for the root, super, and admin accounts, which makes it easier for context-dependent attackers to obtain sensitive information via a brute-force attack.


Published

2014-04-17T01:55:05.690

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:C/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.4

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application emc cloud_tiering_appliance_software 9.0 Yes
Application emc cloud_tiering_appliance_software 10.0 Yes
Application emc cloud_tiering_appliance_software 10.0 Yes
Hardware emc cloud_tiering_appliance - Yes
Application emc file_management_appliance_software 7.0 Yes
Hardware emc file_management_appliance - Yes

References