First published: Fri Feb 22 2013(Updated: )
NEC Universal RAID Utility 1.40 Rev 680 and earlier, 2.31 Rev 1492 and earlier, and 2.5 Rev 2244 and earlier does not provide access control, which allows remote attackers to perform arbitrary RAID disk operations via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
NEC Universal RAID Utility | <=1.40 | |
NEC Universal RAID Utility | <=2.5 | |
NEC Universal RAID Utility | <=2.31 | |
NEC Universal RAID Utility | =1.40 | |
NEC Universal RAID Utility | =2.5 | |
NEC Universal RAID Utility | =2.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0706 is rated as a high severity vulnerability due to the lack of access control allowing remote attackers to execute arbitrary RAID disk operations.
To fix CVE-2013-0706, upgrade to NEC Universal RAID Utility version 1.41 or later, 2.32 or later, or 2.6 or later.
CVE-2013-0706 affects NEC Universal RAID Utility versions 1.40 Rev 680 and earlier, 2.31 Rev 1492 and earlier, and 2.5 Rev 2244 and earlier.
Yes, CVE-2013-0706 can be exploited remotely due to insufficient access control, allowing attackers to perform unauthorized RAID operations.
CVE-2013-0706 allows attackers to perform arbitrary RAID disk operations that could compromise data integrity and availability.