PT-2015-4702 · Emc · Emc Autostart

Published

2015-05-07

·

Updated

2016-04-01

·

CVE-2015-0538

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EMC AutoStart versions 5.4.x through 5.5.x before 5.5.0.508 HF4
Description The issue allows remote attackers to execute arbitrary commands via crafted packets. It involves SQL injection and command injection vulnerabilities in the ftagent.exe component of EMC AutoStart, specifically affecting various opcodes and subcodes, such as Opcode 83 Subcode 22, Opcode 20 Subcode 2060, Opcode 85 Subcode 33, and Opcode 20 Subcode 2219.
Recommendations For versions 5.4.x through 5.5.x before 5.5.0.508 HF4, update to version 5.5.0.508 HF4 or later to resolve the issue. As a temporary workaround, consider restricting access to the ftagent.exe component until a patch is applied. Avoid using the vulnerable opcodes and subcodes in the ftAgent protocol until the issue is resolved.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-0538
ZDI-15-171
ZDI-15-172
ZDI-15-173
ZDI-15-174
ZDI-15-175

Affected Products

Emc Autostart