First published: Thu Sep 14 2017(Updated: )
EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various privileges. Affected accounts are: "Apollo System Test", "emc.dpa.agent.logon" and "emc.dpa.metrics.logon". An attacker with knowledge of the password could potentially use these accounts via REST APIs to gain unauthorized access to EMC Data Protection Advisor (including potentially access with administrative privileges).
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Data Protection Advisor | =6.3.0 | |
Dell EMC Data Protection Advisor | =6.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8013 is a vulnerability in EMC Data Protection Advisor versions 6.3.x and 6.4.x before patch 67 and 130 respectively that allows unauthorized access to undocumented accounts with hard-coded passwords.
CVE-2017-8013 has a severity rating of 9.8 (Critical).
CVE-2017-8013 affects EMC Data Protection Advisor versions 6.3.x and 6.4.x before patch 67 and 130 respectively.
The affected accounts are "Apollo System Test", "emc.dpa.agent.logon", and "emc.dpa.metrics.logon".
The vulnerability can be exploited by an attacker with knowledge of the hard-coded passwords to gain unauthorized access to the affected accounts.