First published: Sun Jun 19 2016(Updated: )
EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 allows remote authenticated users to bypass intended password-change restrictions by leveraging access to (1) a different account with the same role as a target account or (2) an account's session at an unattended workstation.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Data Domain Operating System | <=5.7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0912 has a medium severity rating due to its potential for unauthorized password changes by authenticated users.
To fix CVE-2016-0912, upgrade to EMC Data Domain OS version 5.7.2.0 or later.
CVE-2016-0912 affects users of EMC Data Domain OS versions 5.4 through 5.7.1.0.
CVE-2016-0912 describes an attack that allows remote authenticated users to bypass password-change restrictions.
The implications of CVE-2016-0912 include potential unauthorized access to user accounts due to insufficient password-change safeguards.