Authentication bypass in EMC Secure Remote Services - CVE-2017-4986

 

Authentication bypass in EMC Secure Remote Services - CVE-2017-4986

Published: June 20, 2017


Vulnerability identifier: #VU7122
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-4986
CWE-ID: CWE-592
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to bypass authentication on the target system.

The weakness exists due to unsafe authentication mechanism. A remote attacker can bypass authentication and potentially read sensitive log data containing usernames and IP addresses.

Successful exploitation of the vulnerability may result in information disclosure.

Affected software

EMC Secure Remote Services

How to mitigate CVE-2017-4986

Update to version 3.20.


External References

Related Security Bulletins