CVE-2018-11062
A malicious user with the knowledge of the default passwords may potentially log in to the system and gain read and write access to certain system files.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may potentially log in to the system and gain read and write access to certain system files.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- dell/emc integrated data protection appliance
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/105764Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2018/Oct/53Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105764Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2018/Oct/53Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.