9
CVSSv2

CVE-2018-1215

Published: 08/03/2018 Updated: 29/03/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An arbitrary file upload vulnerability exists in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions before 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions before 8.4.0.21, Dell EMC VASA Virtual Appliance versions before 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and previous versions). A remote authenticated malicious user may potentially upload arbitrary maliciously crafted files in any location on the web server. By chaining this vulnerability with CVE-2018-1216, the attacker may use the default account to exploit this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dell emc vmax embedded management

dell emc unisphere for vmax virtual appliance

dell emc vasa virtual appliance

dell emc solutions enabler virtual appliance

Recent Articles

Dell EMC squashes pair of VMAX virtual appliance bugs
The Register • Chris Mellor • 15 Feb 2018

vApp Manager contained undocumented default account

Dell EMC has patched two serious flaws in the management interface for its VMAX enterprise storage systems, one of which could potentially allow a remote attacker to gain unauthorised access to systems. The vendor announced that the VMAX vApp Manager had "Multiple Vulnerabilities" in a security advisory earlier this week. The message said the vApp Manager, embedded in four Dell EMC products, contains two security vulnerabilities. It has reserved a spot on Mitre's Common Vulnerabilities and Expos...