CVE-2021-42370
A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input fields in the device properties.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input fields in the device properties. (Viewing the passwords requires configuring a web browser to display HTML password input fields.)
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.72% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- xorux/lpar2rrd · xorux/stor2rrd
- Source
- cve@mitre.org
References
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-f3qp-4xqq-2wjxThird Party Advisory
- https://lpar2rrd.com/note730.phpRelease Notes, Vendor Advisory
- https://stor2rrd.com/note730.phpRelease Notes, Vendor Advisory
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-f3qp-4xqq-2wjxThird Party Advisory
- https://lpar2rrd.com/note730.phpRelease Notes, Vendor Advisory
- https://stor2rrd.com/note730.phpRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.