First published: Fri Sep 28 2018(Updated: )
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing Role-Based Authorization control implemented only in Unisphere GUI.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Unity Firmware | <4.3.1.1525703027 | |
Dell EMC Unity Firmware | ||
Dell EMC UnityVSA | <4.3.1.1525703027 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1250 is rated as Medium severity due to its potential for unauthorized access.
To fix CVE-2018-1250, upgrade Dell EMC Unity or UnityVSA to version 4.3.1.1525703027 or later.
CVE-2018-1250 affects users of Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027.
CVE-2018-1250 is an Authorization Bypass vulnerability that allows remote authenticated users to exploit certain APIs.
An attacker exploiting CVE-2018-1250 could read files on the NAS server by bypassing Role-Based Authorization.