CWE
264
Advisory Published
Updated

CVE-2013-0706

First published: Fri Feb 22 2013(Updated: )

NEC Universal RAID Utility 1.40 Rev 680 and earlier, 2.31 Rev 1492 and earlier, and 2.5 Rev 2244 and earlier does not provide access control, which allows remote attackers to perform arbitrary RAID disk operations via unspecified vectors.

Credit: vultures@jpcert.or.jp

Affected SoftwareAffected VersionHow to fix
NEC Universal RAID Utility<=1.40
NEC Universal RAID Utility<=2.5
NEC Universal RAID Utility<=2.31
NEC Universal RAID Utility=1.40
NEC Universal RAID Utility=2.5
NEC Universal RAID Utility=2.31

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2013-0706?

    CVE-2013-0706 is rated as a high severity vulnerability due to the lack of access control allowing remote attackers to execute arbitrary RAID disk operations.

  • How do I fix CVE-2013-0706?

    To fix CVE-2013-0706, upgrade to NEC Universal RAID Utility version 1.41 or later, 2.32 or later, or 2.6 or later.

  • What software is affected by CVE-2013-0706?

    CVE-2013-0706 affects NEC Universal RAID Utility versions 1.40 Rev 680 and earlier, 2.31 Rev 1492 and earlier, and 2.5 Rev 2244 and earlier.

  • Can CVE-2013-0706 be exploited remotely?

    Yes, CVE-2013-0706 can be exploited remotely due to insufficient access control, allowing attackers to perform unauthorized RAID operations.

  • What types of operations can be performed due to CVE-2013-0706?

    CVE-2013-0706 allows attackers to perform arbitrary RAID disk operations that could compromise data integrity and availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203