Information disclosure in EMC NetWorker Server - CVE-2018-11050

 

Information disclosure in EMC NetWorker Server - CVE-2018-11050

Published: July 31, 2018 / Updated: July 31, 2018


Vulnerability identifier: #VU14127
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11050
CWE-ID: CWE-312
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to obtain potentially sensitive information.

The vulnerability exists due to a flaw in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. A remote attacker monitoring the local network collision domain can obtain clear text passwords that are sent to the remote AMQP service and access the target component with the privileges of the target user.


Affected software

EMC NetWorker Server

How to mitigate CVE-2018-11050

The vulnerability has been addressed in the versions 9.1.1.9, 9.2.1.4, 18.1.0.2.

EMC NetWorker Server - addressed in versions 9.1.1.9, 9.2.1.4, 18.1.0.2

External References

Related Security Bulletins