CVE-2024-22432
Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the disclosure of configured MySQL Database user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application Database with privileges of the compromised account.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.14%
- CWE
- CWE-256
- Published
- 2024-01-25
- Last modified
- 2026-03-13
Affected products
- Dell NetWorker Module for Databases and Applications - Oracle
- Dell NetWorker Module for Databases and Applications - Oracle
- Dell NetWorker Module for Databases and Applications - Oracle
- Dell NetWorker Module for Databases and Applications - Oracle
- Dell NetWorker Module for Databases and Applications - Oracle
Weakness type
Related vulnerabilities
- CVE-2026-19051 — Plaintext Storage of User Credentials in Menulux Software's Menulux Portal
- CVE-2026-15933 — Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise)
- CVE-2021-38489 — HDD Password Stored In Plaintext
- CVE-2026-82453 — rust-iot-platform Cleartext Password Storage via User Model
- CVE-2026-55765 — CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the PostgreSQL superuser credential and achieve RCE in the database pod
- CVE-2026-55164 — Lemur: Plaintext password storage in Lemur user-update path
- CVE-2026-50641 — Plaintext password storage in Streamsoft Business Intelligence
- CVE-2026-41874 — Hard-coded admin credentials in Quick.Cart