Rewterz
Rewterz Threat Advisory –CVE-2021-34398 – NVIDIA Data Center GPU Manager Security Vulnerability
August 9, 2021
Rewterz
Rewterz Threat Alert – FormBook Malware – Fresh IOCs
August 9, 2021

Rewterz Threat Advisory –Multiple Dell EMC NetWorker Security Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-21558

Dell EMC NetWorker contains an Information Disclosure vulnerability. A local administrator of the gstd system may potentially exploit this vulnerability to read LDAP credentials from local logs and use the stolen credentials to make changes to the network domain.

CVE-2021-21559

Dell EMC NetWorker versions contain an Improper Certificate Validation vulnerability in the client (NetWorker Management Console) components which uses SSL encrypted connection in order to communicate with the application server. An unauthenticated attacker in the same network collision domain as the NetWorker Management Console client may potentially exploit this vulnerability to perform man-in-the-middle attacks to intercept and tamper the traffic between the client and the application server.

Impact

  • Credential Theft
  • Information Disclosure

Affected Vendors

Dell

Affected Products

  • Dell EMC NetWorker

Remediation

For the complete list of affected products and mitigation techniques refer to the vendor website at

https://www.dell.com/support/kbdoc/en-pk/000186638/dsa-2021-104-dell-emc-networker-security-update-for-multiple-vulnerabilities