CVE-2018-1206
Summary
| CVE | CVE-2018-1206 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-12 17:29:00 UTC |
| Updated | 2018-04-13 14:51:00 UTC |
| Description | Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardcoded database account with administrative privileges. The affected account is "apollosuperuser." An attacker with local access to the server where DPA Datastore Service is installed and knowledge of the password may potentially gain unauthorized access to the database. Note: The Datastore Service database cannot be accessed remotely using this account. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Data Protection Advisor | 6.3.0 | All | All | All |
| Application | Emc | Data Protection Advisor | 6.4.0 | All | All | All |
| Application | Emc | Data Protection Advisor | 6.3.0 | All | All | All |
| Application | Emc | Data Protection Advisor | 6.4.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: DSA-2018-020: Dell EMC Data Protection Advisor Hardcoded Password Vulnerability | CONFIRM | seclists.org | Mailing List, Third Party Advisory |
| EMC Data Protection Advisor Hardcoded Password Lets Local Users Gain Administrative Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| EMC Data Protection Advisor Local Hardcoded Credentials Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.