Dell EMC patches critical flaws in VMAX enterprise storage systemsDatapro Infotech
Dell EMC patches critical flaws in VMAX enterprise storage systems
Remote, unauthenticated attackers could exploit the vulnerabilities to fully compromise the systems
Another critical vulnerability was fixed in the vApp Manager application for Unisphere, which runs on port 5480. This application has a class called GetSymmCmdCommand through which attackers could execute arbitrary commands without authentication, the Digital Defense researchers said in their advisory.
VApp Manager has another critical vulnerability in the RemoteServiceHandler class that allows unauthenticated users to bypass authentication and call several other sensitive classes.
Successful exploitation of this flaw can lead to arbitrary command execution with root privileges, the ability to add new admin users, and complete compromise of the virtual appliance.
The other three vulnerabilities are also in vApp Manager and are rated as high severity instead of critical because they require authentication to exploit. However, all of them allow a low-privileged user to execute arbitrary commands as root and could lead to a full system compromise.