Dell VMAX Remote Code Execution Vulnerabilities
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Dell EMC Unisphere for VMAX Virtual Appliance
- Dell EMC Unisphere for VMAX Virtual Appliance - versions prior to 8.4.0.18
- Dell EMC Solutions Enabler Virtual Appliance - versions prior to 8.4.0.21
- Dell EMC VASA Virtual Appliance - versions prior to 8.4.0.514
- Dell EMC VMAX Embedded Management (eManagement) - versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier)
Dell EMC Solutions Enabler Virtual Appliance
Dell EMC VASA Virtual Appliance
Dell EMC VMAX Embedded Management (eManagement)
Threat details
The first vulnerability allows a remote authenticated attacker to upload files to any location on the web server. The second vulnerability is an undocumented default account with a hard-coded password which could be used in combination with the first vulnerability to compromise the affected system.
Remediation steps
Last edited: 17 February 2020 12:41 pm