Improper access control in EMC Integrated Data Protection Appliance and EMC Avamar - CVE-2018-1217

 

Improper access control in EMC Integrated Data Protection Appliance and EMC Avamar - CVE-2018-1217

Published: April 10, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU11623
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1217
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information and write arbitrary files on the target system.

The weakness exists due to improper access control. A remote attacker can view or modify the LDLS credentials, which are used to authenticate to Dell EMC Online Support.

Affected software

EMC Integrated Data Protection Appliance
EMC Avamar

How to mitigate CVE-2018-1217

Update to 7.3.1 - HOTFIX 290316, 7.4.1 - HOTFIX 291882 or 7.5.0 - HOTFIX 291881.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins