CVE-2021-21508 PUBLISHED

Assigner: dell
Reserved: 04.01.2021 Published: 22.05.2026 Updated: 22.05.2026

Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 6.7

Product Status

Vendor Dell
Product VxRail
Versions Default: unaffected
  • affected from 0 to 7.0.200 (excl.)

References

Problem Types

  • CWE-532: Insertion of Sensitive Information into Log File CWE