First published: Sun May 19 2013(Updated: )
EMC VNX Control Station before 7.1.70.2 and Celerra Control Station before 6.0.70.1 have an incorrect group ownership for unspecified script files, which allows local users to gain privileges by leveraging nasadmin group membership.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC VNX Control Station | <=7.1.70.1 | |
EMC VNX | =5100 | |
EMC VNX | =5300 | |
EMC VNX | =5500 | |
EMC VNX | =5700 | |
EMC VNX | =7500 | |
Emc Celerra Control Station | <=6.0.70.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3270 has a moderate severity rating due to the potential for local privilege escalation.
To fix CVE-2013-3270, upgrade EMC VNX Control Station to version 7.1.70.2 or later and Celerra Control Station to version 6.0.70.1 or later.
CVE-2013-3270 affects users of EMC VNX Control Station prior to version 7.1.70.2 and Celerra Control Station prior to version 6.0.70.1.
CVE-2013-3270 allows local users to gain elevated privileges by exploiting incorrect group ownership of certain script files.
Vulnerable systems include EMC VNX Control Station versions up to 7.1.70.1 and Celerra Control Station versions up to 6.0.70.0.