Improper access control in EMC Integrated Data Protection Appliance and EMC Avamar - CVE-2018-1217
Published: April 10, 2018 / Updated: June 17, 2021
Vulnerability identifier: #VU11623
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1217
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information and write arbitrary files on the target system.
The weakness exists due to improper access control. A remote attacker can view or modify the LDLS credentials, which are used to authenticate to Dell EMC Online Support.
The weakness exists due to improper access control. A remote attacker can view or modify the LDLS credentials, which are used to authenticate to Dell EMC Online Support.
Affected software
EMC Integrated Data Protection Appliance
EMC Avamar
EMC Avamar
How to mitigate CVE-2018-1217
Update to 7.3.1 - HOTFIX 290316, 7.4.1 - HOTFIX 291882 or 7.5.0 - HOTFIX 291881.