Vulnerabilities > CVE-2018-1250 - Incorrect Authorization vulnerability in Dell EMC Unity Firmware and EMC Unityvsa

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
dell
CWE-863

Summary

Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing Role-Based Authorization control implemented only in Unisphere GUI.

Vulnerable Configurations

Part Description Count
OS
Dell
2
Hardware
Dell
1

Common Weakness Enumeration (CWE)