EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0514
Reference (s):
- BID:72257
- URL: http://www.securityfocus.com/bid/72257
- BUGTRAQ:20150120 ESA-2015-004: EMC M&R (Watch4Net) Multiple Vulnerabilities
- URL: http://archives.neohapsis.com/archives/bugtraq/2015-01/0092.html
- BUGTRAQ:20150318 EMC M&R (Watch4net) data storage collector credentials are not properly protected