CVE-2021-21547
Description
Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability when the Dell Upgrade Readiness Utility is run on the system. The credentials of the Unisphere Administrator are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell Unity, UnityVSA, and Unity XT prior to 5.0.7.0.5.008 store the Unisphere Administrator password in plain text when the Upgrade Readiness Utility runs, allowing local high-privilege users to steal credentials.
Vulnerability
Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability [1]. When the Dell Upgrade Readiness Utility is executed on the system, the credentials of the Unisphere Administrator are written to a file or log in plain text [1]. No special configuration beyond running the utility is required to trigger this exposure.
Exploitation
A local attacker with high privileges (e.g., root or administrator access) on the affected Dell Unity system can access the file containing the plain-text password [1]. The attacker does not need network access or user interaction; read access to the storage location is sufficient. The sequence involves locating the stored credential file after the Upgrade Readiness Utility has been run and extracting the administrator password.
Impact
Successful exploitation grants the attacker the privileges of the Unisphere Administrator, which include full administrative control over the Dell Unity storage system [1]. This results in a complete compromise of confidentiality, integrity, and availability of the storage platform (CVSS 6.4, vector AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H) [1].
Mitigation
Dell has fixed this vulnerability in Unity, UnityVSA, and Unity XT version 5.0.7.0.5.008 and later [1]. Organizations should upgrade to the patched release. No workaround or KEV listing has been published; the only mitigation is applying the update.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/000185484mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.