CVE-2014-4620

EMC NetWorker Module for MEDITECH <3.0 build 90 - Info Disclosure

Title source: llm
STIX 2.1

Description

The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files.

References (6)

Core 6
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2014-10/0145.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031116
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70726
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/97756
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61952

Scores

EPSS 0.0006
EPSS Percentile 19.8%

Details

CWE
CWE-200
Status published
Products (2)
emc/networker
meditech/meditech 3.0 87 (2 CPE variants)
Published Oct 25, 2014
Tracked Since Feb 18, 2026