Vulnerabilities > CVE-2018-1250 - Incorrect Authorization vulnerability in Dell EMC Unity Firmware and EMC Unityvsa

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
dell
CWE-863

Summary

Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing Role-Based Authorization control implemented only in Unisphere GUI.

Vulnerable Configurations

Part Description Count
OS
Dell
2
Hardware
Dell
1

Common Weakness Enumeration (CWE)