Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDell Emc Solutions Enabler Virtual Appliance
APPDell< 9.2.3.6Dell Emc Unisphere For Powermax
APPDell< 9.2.3.2210.0.0.0 – 10.0.0.5 (bez)Dell Emc Unisphere For Powermax Virtual Appliance
APPDell< 9.2.3.22Dell Emc Vasa Provider Virtual Appliance
APPDell< 9.2.4.15Dell Powermax Os
OSDell5978Dell Solutions Enabler
APPDell10.0.0.0 – 10.0.0.5 (bez)< 9.2.3.6Dell Unisphere 360
APPDell< 9.2.3.12Dell Vasa Provider
APPDell< 9.2.4.22
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Powiązane podatności
CVE-2018-1183CRITICAL9.8PL ✓ten sam produkt
XXE Injection w komponentach ECOM systemów Dell EMC (RCE/ujawnienie danych)
CVE-2018-1216CRITICAL9.8PL ✓ten sam produkt
Zakodowane na stałe hasło w vApp Manager — Dell EMC VMAX
CVE-2017-4997CRITICAL9.8PL ✓ten sam produkt
RCE bez uwierzytelnienia w EMC VASA Provider Virtual Appliance
CVE-2023-48660HIGH7.5ten sam produkt
Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker c...
CVE-2023-48662HIGH7.2ten sam produkt
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious us...