10
CVSSv2

CVE-2018-1216

Published: 08/03/2018 Updated: 29/03/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A hard-coded password vulnerability exists in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions before 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions before 8.4.0.21, Dell EMC VASA Virtual Appliance versions before 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and previous versions). They contain an undocumented default account (smc) with a hard-coded password that may be used with certain web servlets. A remote attacker with the knowledge of the hard-coded password and the message format may use vulnerable servlets to gain unauthorized access to the system. Note: This account cannot be used to log in via the web user interface.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dell emc vmax embedded management

dell emc solutions enabler virtual appliance

dell emc vasa virtual appliance

dell emc unisphere for vmax virtual appliance

Recent Articles

Dell EMC squashes pair of VMAX virtual appliance bugs
The Register • Chris Mellor • 15 Feb 2018

vApp Manager contained undocumented default account

Dell EMC has patched two serious flaws in the management interface for its VMAX enterprise storage systems, one of which could potentially allow a remote attacker to gain unauthorised access to systems. The vendor announced that the VMAX vApp Manager had "Multiple Vulnerabilities" in a security advisory earlier this week. The message said the vApp Manager, embedded in four Dell EMC products, contains two security vulnerabilities. It has reserved a spot on Mitre's Common Vulnerabilities and Expos...