Threat Encyclopedia

Dell.EMC.VMAX.Virtual.Appliance.Manager.Authentication.Bypass

description-logoDescription

This indicates an attack attempt to exploit an Authentication Bypass Vulnerability in EMC Dell EMC VMAX Embedded Management (eManagement).
The vulnerability is due to an error in the vulnerable application when handling a maliciously crafted request. An attacker can exploit this to gain administrator privileges in the affected system.

affected-products-logoAffected Products

EMC Dell EMC Solutions Enabler Virtual Appliance prior to 8.4.0.21
EMC Dell EMC Unisphere for VMAX Virtual Appliance prior to 8.4.0.18
EMC Dell EMC VASA Virtual Appliance prior to 8.4.0.516
EMC Dell EMC VMAX Embedded Management (eManagement) prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier)

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor:
http://seclists.org/fulldisclosure/2018/Feb/att-38/DSA-2018-024.txt

CVE References

CVE-2018-1216