7.8
CVSSv3

CVE-2018-11064

Published: 05/10/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability to alter multiple library files in service tools that might result in arbitrary code execution with elevated privileges. No user file systems are directly affected by this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dell emc unityvsa operating environment

dell emc unity operating environment

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 DSA-2018-141: Dell EMC Unity Family Incorrect File Permissions vulnerability Dell EMC Identifier: DSA-2018-141 CVE Identifier: CVE-2018-11064 Severity Rating: CVSS v3 Base Score: 78 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Affected products: Dell EMC Unity Operating Environment (OE) versions 4 ...