CVE-2021-36317
Description
Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell EMC Avamar Server 19.4 stores credentials in plain text in AvInstaller, enabling local attackers to disclose and reuse user credentials.
Vulnerability
CVE-2021-36317 is a plain-text password storage vulnerability in the AvInstaller component of Dell EMC Avamar Server version 19.4. The software stores certain user credentials in an unencrypted (plain-text) format, violating secure storage practices. This flaw affects only Avamar Server 19.4 [1].
Exploitation
An attacker must have local access to the affected Avamar Server and sufficient privileges to read the stored configuration files. No special network position or user interaction is required beyond local authentication. The attacker can locate the plain-text credentials within the AvInstaller data and extract them [1].
Impact
Successful exploitation leads to disclosure of user credentials. The attacker can then use those credentials to access the vulnerable application or other associated services with the privileges of the compromised account. Because the attacker already has local access, the additional credential exposure may allow privilege escalation or lateral movement within the environment. The CVSS 3.1 vector (AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) indicates potential for high confidentiality, integrity, and availability impact [1].
Mitigation
Dell has released a security update as part of DSA-2021-204 on 2021-12-21. Users should upgrade to the fixed version of Dell EMC Avamar Server or apply the vendor-provided patch. The advisory does not note any interim workaround. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: =19.4
- Range: =19.4
- Range: 19.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- security.gentoo.org/glsa/202210-09mitrevendor-advisory
- www.dell.com/support/kbdoc/000193369mitre
News mentions
0No linked articles in our index yet.