CVE-2018-1250
28.09.2018, 18:29
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing Role-Based Authorization control implemented only in Unisphere GUI.Enginsight
Vendor | Product | Version |
---|---|---|
dell | emc_unity_firmware | 𝑥 < 4.3.1.1525703027 |
dell | emc_unityvsa | 𝑥 < 4.3.1.1525703027 |
𝑥
= Vulnerable software versions