VulnerabilityModified
CVE-2002-0114
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file.
MEDIUM 4.6EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- emc/networker
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/249420Vendor Advisory
- http://www.iss.net/security_center/static/7898.phpVendor Advisory
- http://www.securityfocus.com/bid/3842
- http://online.securityfocus.com/archive/1/249420Vendor Advisory
- http://www.iss.net/security_center/static/7898.phpVendor Advisory
- http://www.securityfocus.com/bid/3842
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.