
The Dell EMC VMAX storage platform. Credit: Dell EMC
Lucian Constantin
IDG News Service
Oct 3, 2016 12:05 PM
Remote, unauthenticated attackers could exploit the vulnerabilities to fully compromise the systems
Lucian Constantin
IDG News Service
Oct 3, 2016 12:05 PM
Remote, unauthenticated attackers could exploit the vulnerabilities to fully compromise the systems
Dell EMC has fixed six flaws in its management interfaces for VMAX enterprise storage systems, including three vulnerabilities that are rated critical and could lead to the exposure of sensitive files or a complete system compromise.
One of the critical flaws is located in the Unisphere for VMAX enterprise storage arrays, an appliance that provides a web-based management interface to provision, manage, and monitor such systems.
More specifically, the flaw is in the GraniteDS library that provides server-side support for the Flash-based portion of the Unisphere web application. According to researchers from vulnerability management firm Digital Defense, the issue allows unauthenticated attackers to retrieve arbitrary text files from the virtual appliance with root privileges.
Another critical vulnerability was fixed in the vApp Manager application for
One of the critical flaws is located in the Unisphere for VMAX enterprise storage arrays, an appliance that provides a web-based management interface to provision, manage, and monitor such systems.
More specifically, the flaw is in the GraniteDS library that provides server-side support for the Flash-based portion of the Unisphere web application. According to researchers from vulnerability management firm Digital Defense, the issue allows unauthenticated attackers to retrieve arbitrary text files from the virtual appliance with root privileges.
Another critical vulnerability was fixed in the vApp Manager application for
