7.8
CVSSv3

CVE-2018-1206

Published: 12/03/2018 Updated: 13/04/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Dell EMC Data Protection Advisor versions before 6.3 Patch 159 and Dell EMC Data Protection Advisor versions before 6.4 Patch 110 contain a hardcoded database account with administrative privileges. The affected account is "apollosuperuser." An attacker with local access to the server where DPA Datastore Service is installed and knowledge of the password may potentially gain unauthorized access to the database. Note: The Datastore Service database cannot be accessed remotely using this account.

Vulnerable Product Search on Vulmon Subscribe to Product

emc data protection advisor 6.3.0

emc data protection advisor 6.4.0