PT-2018-11032 · Dell Emc+1 · Openmanage Essentials+2
Published
2018-02-12
·
Updated
2018-03-12
·
CVE-2018-1214
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell EMC SupportAssist Enterprise versions 1.1 through 1.2
Description
The issue arises from the creation of a local Windows user account named
OMEAdapterUser with a default password during the installation of Dell EMC SupportAssist Enterprise. This account remains after upgrading from version 1.1 to 1.2. Knowledge of the default password can allow unauthorized access to the management console. If SupportAssist Enterprise is installed on a server running OpenManage Essentials (OME), the OmeAdapterUser account is added to the OmeAdministrators group, potentially allowing an unauthorized person with the default password to gain access to the affected OME installation with OmeAdministrators privileges.Recommendations
For versions 1.1 through 1.2, update to version 1.2.1 to resolve the issue.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Emc Supportassist Enterprise
Openmanage Essentials
Windows