First published: Wed Aug 29 2012(Updated: )
EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows remote attackers to obtain GUI administrative access by sending a crafted file during the authentication phase.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Cloud Tiering Appliance | <=9.0 | |
EMC Cloud Tiering Appliance Software | <=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2285 is considered a high severity vulnerability due to its ability to allow unauthorized remote access to administrative features.
To mitigate CVE-2012-2285, upgrade to a version of EMC Cloud Tiering Appliance or Cloud Tiering Appliance Virtual Edition that is later than version 9.0.
CVE-2012-2285 can enable attackers to gain administrative control over the affected EMC Cloud Tiering Appliance systems.
Yes, CVE-2012-2285 is exploitable remotely by attackers through crafted files during the authentication phase.
CVE-2012-2285 affects EMC Cloud Tiering Appliance and Cloud Tiering Appliance Virtual Edition versions 9.0 and earlier.