Dell EMC Zero-Day Vulnerabilities
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Dell EMC RecoverPoint
- Dell EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0
- Dell EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x
- Dell EMC Integrated Data Protection Appliance (IDPA) 2.0
Threat details
The first vulnerability exploits the "getFileContents" method of the "UserInputService" class. This method does not perform any validation of filename parameters supplied by a user before retrieving the requested file. Additionally, the web server serving these request runs as root, meaning any file can be retrieved.
The second vulnerability allows a user to to upload files to an arbitrary location. The "saveFileContents" method of the "UserInputService" accepts a single string and splits it on a specific character. The first half of the string describes the filepath, with the second describing the data to be written.
The final vulnerability can be combined with the first two to fully compromise a system. Authentication is performed via a POST including username, password and wsURL parameters, an arbitrary URL used by the server to send a Simple Object Access Protocol (SOAP) request. If this SOAP request is successful a valid session ID is returned, a properly formed request will work across multiple servers.
Remediation steps
| Type | Step |
|---|---|
|
CVE Vulnerabilities
Last edited: 17 February 2020 12:41 pm