First published: Thu Mar 22 2012(Updated: )
Absolute path traversal vulnerability in logShow.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to read arbitrary files via a full pathname in the file parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quantum Scalar I500 Firmware | <=i7.0.2 | |
Quantum Scalar I500 Firmware | =i2 | |
Quantum Scalar I500 Firmware | =i3 | |
Quantum Scalar I500 Firmware | =i3.1 | |
Quantum Scalar I500 Firmware | =i4 | |
Quantum Scalar I500 Firmware | =i5 | |
Quantum Scalar I500 Firmware | =i5.1 | |
Quantum Scalar I500 Firmware | =i6 | |
Quantum Scalar I500 Firmware | =i6.1 | |
Quantum Scalar I500 Firmware | =i7 | |
Quantum Scalar I500 Firmware | =i7.0.1 | |
Quantum Scalar I500 Firmware | =sp4 | |
Quantum Scalar I500 Firmware | =sp4.2 | |
Quantum Scalar i500 | =5u | |
Quantum Scalar i500 | =14u | |
Quantum Scalar i500 | =23u | |
Dell Powervault ML6000 Firmware | =585g.gs003 | |
Dell Powervault ML6000 | =32u | |
Dell Powervault ML6000 | =41u | |
Dell Powervault ML6010 | =5u | |
Dell PowerVault ML6020 | =14u | |
Dell Powervault Ml6030 | =23u |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1841 has a moderate severity rating, as it allows remote attackers to read arbitrary files on affected systems.
CVE-2012-1841 affects Quantum Scalar i500 tape libraries and Dell ML6000 tape libraries with specific firmware versions.
To mitigate CVE-2012-1841, upgrade affected firmware to version i7.0.3 or higher for Quantum Scalar i500 and A20-00 or higher for Dell ML6000.
CVE-2012-1841 is classified as an absolute path traversal vulnerability.
Yes, CVE-2012-1841 can be exploited remotely, allowing attackers access to sensitive files.