Dell EMC ESRS Virtual Edition Multiple Vulnerabilities

BID:105694

CVE-2018-11079 | CVE-2018-11080 | CVE-2018-15765 |

Info

Dell EMC ESRS Virtual Edition Multiple Vulnerabilities

Bugtraq ID: 105694
Class: Design Error
CVE: CVE-2018-11080
CVE-2018-11079
CVE-2018-15765
Remote: Yes
Local: Yes
Published: Oct 15 2018 12:00AM
Updated: Oct 15 2018 12:00AM
Credit: Dell
Vulnerable: Dell ESRS Virtual Edition 3.28
Dell ESRS Virtual Edition 3.24
Dell ESRS Virtual Edition 3.10
Dell ESRS Virtual Edition 3.08
Not Vulnerable: Dell ESRS Virtual Edition 3.32.00.08

Discussion

Dell EMC ESRS Virtual Edition Multiple Vulnerabilities

Dell EMC ESRS virtual edition is prone to the following multiple security vulnerabilities.

1. An insecure file permission vulnerability
2. A plaintext password storage vulnerability
3. A information disclosure vulnerability

Successfully exploiting this issue can allow an attacker to obtain sensitive information , to bypass certain security restrictions to perform unauthorized actions and use the sensitive data available that may aid in launching further attacks.

Exploit / POC

Dell EMC ESRS Virtual Edition Multiple Vulnerabilities

References

Dell EMC ESRS Virtual Edition Multiple Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report