PT-2018-1125 · Dell Emc · Dell Emc Unisphere For Vmax Virtual Appliance+3

Carlos Perez

·

Published

2018-02-12

·

Updated

2018-03-29

·

CVE-2018-1216

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18 Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21 Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514 Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4
Description The issue is related to the use of hardcoded credentials in the vApp Manager component of Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement). This allows a remote attacker to gain unauthorized access to the system using certain web servlets and the knowledge of the hardcoded password. The undocumented default account smc with a hardcoded password is the key factor in this issue.
Recommendations For Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, update to version 8.4.0.18 or later. For Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, update to version 8.4.0.21 or later. For Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, update to version 8.4.0.514 or later. For Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4, update to a version later than 1.4. As a temporary workaround, consider restricting access to the vulnerable web servlets until a patch is available.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00551
CVE-2018-1216

Affected Products

Dell Emc Solutions Enabler Virtual Appliance
Dell Emc Unisphere For Vmax Virtual Appliance
Dell Emc Vasa Virtual Appliance
Dell Emc Vmax Embedded Management