CVE-2018-1250Incorrect Authorization in EMC Unity

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 73.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 28
Latest updateMay 13

Description

Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing Role-Based Authorization control implemented only in Unisphere GUI.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDdell/emc_unityvsa< 4.3.1.1525703027
CVEListV5dell_emc/dell_emc_unityvsaunspecified4.3.1.1525703027
CVEListV5dell_emc/dell_emc_unityunspecified4.3.1.1525703027
NVDdell/emc_unity_firmware< 4.3.1.1525703027

🔴Vulnerability Details

2
GHSA
GHSA-r6ff-xjxr-8vfh: Dell EMC Unity and UnityVSA versions prior to 42022-05-13
CVEList
CVE-2018-1250: Dell EMC Unity and UnityVSA versions prior to 42018-09-28

💬Community

1
Bugzilla
CVE-2018-16412 ImageMagick: heap-based buffer over-read in the ParseImageResourceBlocks function in coders/psd.c2018-09-04
CVE-2018-1250 — Incorrect Authorization in EMC Unity | cvebase