A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input fields in the device properties. (Viewing the passwords requires configuring a web browser to display HTML password input fields.)
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/orangecertcc/security-research/security/advisories/GHSA-f3qp-4xqq-2wjx | Third Party Advisory | 
| https://lpar2rrd.com/note730.php | Release Notes Vendor Advisory | 
| https://stor2rrd.com/note730.php | Release Notes Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2021-11-08 05:15
Updated : 2022-07-29 12:46
NVD link : CVE-2021-42370
Mitre link : CVE-2021-42370
CVE.ORG link : CVE-2021-42370
JSON object : View
Products Affected
                xorux
- stor2rrd
 - lpar2rrd
 
CWE
                
                    
                        
                        CWE-312
                        
            Cleartext Storage of Sensitive Information
