Overview
- Description
- EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.
- Source
- security_alert@emc.com
- NVD status
- Analyzed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-290
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:dell:emc_unisphere:*:*:*:*:*:vmax:*:*", "vulnerable": true, "matchCriteriaId": "C1FC69FD-C0C7-4849-95C9-7EFDCCE57B80", "versionEndExcluding": "8.4.0.15" }, { "criteria": "cpe:2.3:a:emc:solutions_enabler:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33F51A90-95C2-4577-BAAA-CDF32AD7EEED", "versionEndExcluding": "8.4.0.15" }, { "criteria": "cpe:2.3:a:emc:vasa:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E7F2982-31F7-4027-A856-1517195597CB", "versionEndExcluding": "8.4.0.512" }, { "criteria": "cpe:2.3:a:emc:vmax_emanagement:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC2E457F-F761-4617-B47D-F9B77373621C", "versionEndIncluding": "1.4" } ], "operator": "OR" } ] } ]