CVE-2018-1184
Summary
| CVE | CVE-2018-1184 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-03 16:29:00 UTC |
| Updated | 2021-05-24 14:10:00 UTC |
| Description | An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3. Command injection vulnerability in Boxmgmt CLI may allow a malicious user with boxmgmt privileges to bypass Boxmgmt CLI and run arbitrary commands with root privileges. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dell | Emc Recoverpoint | All | All | All | All |
| Application | Dell | Emc Recoverpoint | 5.1.0.0 | All | All | All |
| Application | Dell | Emc Recoverpoint For Virtual Machines | All | All | All | All |
| Application | Emc | Recoverpoint | All | All | All | All |
| Application | Emc | Recoverpoint | 5.1.0.0 | All | All | All |
| Application | Emc | Recoverpoint | All | All | All | All |
| Application | Emc | Recoverpoint | 5.1.0.0 | All | All | All |
| Application | Emc | Recoverpoint For Virtual Machines | All | All | All | All |
| Application | Emc | Recoverpoint For Virtual Machines | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: ESA-2018-015: EMC RecoverPoint Command Injection Vulnerabilities | CONFIRM | seclists.org | Mailing List, Patch, Third Party Advisory |
| EMC RecoverPoint Command Injection Bugs Let Local Users Obtain Root Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.