CVE-2013-3285

low
Published 2013-11-02 · Modified 2026-04-29
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

The NetWorker Management Console (NMC) in EMC NetWorker 8.0.x before 8.0.2.3, when using Active Directory/LDAP for authentication, allows remote authenticated users to discover cleartext administrator passwords via (1) unspecified NMC audit reports or (2) requests to RAP resources.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
emcnetworker8.0
emcnetworker8.0.0.1
emcnetworker8.0.0.2
emcnetworker8.0.0.3
emcnetworker8.0.0.4
emcnetworker8.0.0.5
emcnetworker8.0.0.6
emcnetworker8.0.1.3
emcnetworker8.0.1.4
emcnetworker8.0.1.5
emcnetworker8.0.1.6
emcnetworker8.0.2.0
emcnetworker8.0.2.1
emcnetworker8.0.2.2

References

CWEs

CWE-310

Verify integrity in audit chain (admin only). AS-IS.