CVE-2018-1250 — Incorrect Authorization in EMC Unity
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 73.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 28
Latest updateMay 13
Description
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing Role-Based Authorization control implemented only in Unisphere GUI.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages4 packages
🔴Vulnerability Details
2💬Community
1Bugzilla▶
CVE-2018-16412 ImageMagick: heap-based buffer over-read in the ParseImageResourceBlocks function in coders/psd.c↗2018-09-04