VYPR
Unrated severityNVD Advisory· Published Dec 21, 2021· Updated Sep 16, 2024

CVE-2021-36317

CVE-2021-36317

Description

Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell EMC Avamar Server 19.4 stores credentials in plain text in AvInstaller, enabling local attackers to disclose and reuse user credentials.

Vulnerability

CVE-2021-36317 is a plain-text password storage vulnerability in the AvInstaller component of Dell EMC Avamar Server version 19.4. The software stores certain user credentials in an unencrypted (plain-text) format, violating secure storage practices. This flaw affects only Avamar Server 19.4 [1].

Exploitation

An attacker must have local access to the affected Avamar Server and sufficient privileges to read the stored configuration files. No special network position or user interaction is required beyond local authentication. The attacker can locate the plain-text credentials within the AvInstaller data and extract them [1].

Impact

Successful exploitation leads to disclosure of user credentials. The attacker can then use those credentials to access the vulnerable application or other associated services with the privileges of the compromised account. Because the attacker already has local access, the additional credential exposure may allow privilege escalation or lateral movement within the environment. The CVSS 3.1 vector (AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) indicates potential for high confidentiality, integrity, and availability impact [1].

Mitigation

Dell has released a security update as part of DSA-2021-204 on 2021-12-21. Users should upgrade to the fixed version of Dell EMC Avamar Server or apply the vendor-provided patch. The advisory does not note any interim workaround. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.