Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-8001


An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear text in temporary log files. The temporary files may potentially be read by an unprivileged user with access to the server where the script was executed to recover exposed credentials.


Published

2017-11-28T07:29:00.337

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 8.4 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell emc_scaleio 2.0.1.0 Yes
Application dell emc_scaleio 2.0.1.1 Yes
Application dell emc_scaleio 2.0.1.2 Yes
Application dell emc_scaleio 2.0.1.3 Yes
Operating System linux linux_kernel - No

References