Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jack Backer

Researcher fromNorthrop Grumman
#38652of 53,635
7.2Total CVSS
Vulnerabilities · 1
PT-2018-10844
7.2
2018-02-03
Emc · Boxmgmt Cli · CVE-2018-1184
**Name of the Vulnerable Software and Affected Versions** EMC RecoverPoint for Virtual Machines versions prior to 5.1.1 EMC RecoverPoint version 5.1.0.0 EMC RecoverPoint versions prior to 5.0.1.3 **Description** An issue was discovered that allows a malicious user with boxmgmt privileges to bypass Boxmgmt CLI and run arbitrary commands with root privileges due to a command injection vulnerability in Boxmgmt CLI. **Recommendations** For EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, update to version 5.1.1 or later. For EMC RecoverPoint version 5.1.0.0, update to a version later than 5.1.0.0. For EMC RecoverPoint versions prior to 5.0.1.3, update to version 5.0.1.3 or later. As a temporary workaround, consider restricting access to the Boxmgmt CLI to minimize the risk of exploitation.