First published: Mon Dec 28 2015(Updated: )
EMC VPLEX GeoSynchrony 5.4 SP1 before P3 and 5.5 before Patch 1 has a default password for the root account, which allows local users to gain privileges by leveraging a login session.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC VPLEX GeoSynchrony | =5.4-sp1 | |
Dell EMC VPLEX GeoSynchrony | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6850 is considered a critical vulnerability due to the default root password allowing unauthorized privilege escalation.
To fix CVE-2015-6850, reset the default root password on affected EMC VPLEX GeoSynchrony versions.
CVE-2015-6850 affects EMC VPLEX GeoSynchrony versions 5.4 SP1 before P3 and 5.5 before Patch 1.
Yes, local users can exploit CVE-2015-6850 to gain elevated privileges by leveraging the default root account.
Yes, a patch is available for EMC VPLEX GeoSynchrony 5.5 and users are advised to upgrade to the latest version.