First published: Fri Mar 16 2018(Updated: )
In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote malicious user could potentially exploit this vulnerability to read unauthorized files by supplying specially crafted strings in input parameters of the application. A malicious user cannot delete or modify any files via this vulnerability.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Storage Manager 2016 | <16.3.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14384 is considered a moderate severity vulnerability due to its potential for unauthorized file access.
To mitigate CVE-2017-14384, upgrade Dell Storage Manager to version 16.3.20 or later.
CVE-2017-14384 allows remote attackers to read unauthorized files on the affected system.
CVE-2017-14384 affects all versions of Dell Storage Manager prior to 16.3.20.
There are no known workarounds for CVE-2017-14384, so upgrading is the recommended solution.