PT-2017-3309 · Emc · Dell Emc Solutions Enabler Virtual Appliance+3

Published

2017-10-30

·

Updated

2021-08-05

·

CVE-2017-14375

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15 EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15 EMC VASA Virtual Appliance versions prior to 8.4.0.512 EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4
Description The issue is related to an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system. This vulnerability is associated with inadequate access control, which could allow a remote attacker to bypass the authentication procedure.
Recommendations For EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, update to version 8.4.0.15 or later. For EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, update to version 8.4.0.15 or later. For EMC VASA Virtual Appliance versions prior to 8.4.0.512, update to version 8.4.0.512 or later. For EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4, update to a version later than 1.4.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00074
CVE-2017-14375
ZDI-17-919

Affected Products

Dell Emc Solutions Enabler Virtual Appliance
Emc Unisphere For Vmax Virtual Appliance
Dell Emc Vasa Virtual Appliance
Dell Emc Vmax Embedded Management