CVE-2021-21558
https://notcve.org/view.php?id=CVE-2021-21558
Dell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A local administrator of the gstd system may potentially exploit this vulnerability to read LDAP credentials from local logs and use the stolen credentials to make changes to the network domain. Dell EMC NetWorker, versiones 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 y 19.4.0.1, contiene una vulnerabilidad de Divulgación de Información. Un administrador local del sistema gstd puede explotar potencialmente esta vulnerabilidad para leer las credenciales LDAP de los registros locales y usar las credenciales robadas para realizar cambios en el dominio de red • https://www.dell.com/support/kbdoc/en-us/000186638/dsa-2021-104-dell-emc-networker-security-update-for-multiple-vulnerabilities • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2020-26183
https://notcve.org/view.php?id=CVE-2020-26183
Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with low privileges may exploit this vulnerability to perform 'nsrmmdbd' operations in an unintended manner. Dell EMC NetWorker versiones anteriores a 19.3.0.2, contiene una vulnerabilidad de autorización inapropiada. Determinados usuarios remotos con pocos privilegios pueden explotar esta vulnerabilidad para llevar a cabo operaciones "nsrmmdbd" de manera involuntaria • https://www.dell.com/support/security/en-us/details/546616/DSA-2020-229-Dell-EMC-NetWorker-Multiple-Security-Vulnerabilities • CWE-285: Improper Authorization CWE-552: Files or Directories Accessible to External Parties •
CVE-2020-26182
https://notcve.org/view.php?id=CVE-2020-26182
Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manner. The vulnerability is not exploitable by users authenticated via LDAP. Dell EMC NetWorker versiones anteriores a 19.3.0.2, contienen una vulnerabilidad de asignación de privilegios incorrecta. Un usuario remoto que no sea LDAP con pocos privilegios puede explotar esta vulnerabilidad para llevar a cabo operaciones relacionadas a "saveset" de manera involuntaria. • https://www.dell.com/support/security/en-us/details/546616/DSA-2020-229-Dell-EMC-NetWorker-Multiple-Security-Vulnerabilities • CWE-266: Incorrect Privilege Assignment CWE-552: Files or Directories Accessible to External Parties •