« Volver al listado

CVE-2013-3287

Estado: ModificadaBaja (1.9)—

EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cleartext LDAP bind password by reading the console.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-3287",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 1.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-11-02T19:55:04.493",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2013-10/0155.html",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/63425",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2013-10/0155.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/63425",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cleartext LDAP bind password by reading the console."
    },
    {
      "lang": "es",
      "value": "EMC Unisphere para VMAX anterior a 1.6.1.6, cuando se utiliza un nivel no especificado del registro de depuración en las configuraciones de LDAP, permite a los usuarios locales descubrir la contraseña LDAP bind sin cifrar mediante la lectura de la consola."
    }
  ],
  "lastModified": "2026-06-16T23:54:50.447",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:emc_unisphere:*:*:*:*:*:vmax:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F147989-66CD-4BAE-B0BA-D2144376D7D1",
              "versionEndIncluding": "1.6"
            },
            {
              "criteria": "cpe:2.3:a:dell:emc_unisphere:1.0:*:*:*:*:vmax:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0A8A0CA-0760-4751-AB8F-DE9B472CA0E7"
            },
            {
              "criteria": "cpe:2.3:a:dell:emc_unisphere:1.1:*:*:*:*:vmax:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69255668-4966-4BBD-91EC-BFFE800D6F5A"
            },
            {
              "criteria": "cpe:2.3:a:dell:emc_unisphere:1.5:*:*:*:*:vmax:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BCFCC0D-F6E5-4FF8-A513-DF5192B98675"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}