First published: Mon Oct 29 2018(Updated: )
Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may potentially log in to the system and gain read and write access to certain system files.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Integrated Data Protection Appliance | >=2.0<=2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11062 refers to a vulnerability in the Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 where undocumented accounts named 'support' and 'admin' have default passwords, making them accessible to malicious users.
CVE-2018-11062 has a severity level of 8.8 (Critical).
The impact of CVE-2018-11062 is that malicious users can gain access to certain system files on the Integrated Data Protection Appliance.
To fix CVE-2018-11062, it is recommended to change the default passwords of the 'support' and 'admin' accounts on Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2.
More information about CVE-2018-11062 can be found at the following references: [http://www.securityfocus.com/bid/105764](http://www.securityfocus.com/bid/105764) and [https://seclists.org/fulldisclosure/2018/Oct/53](https://seclists.org/fulldisclosure/2018/Oct/53).