EMC DiskXtender Hard Coded Authentication Credentials Vulnerability
BID:28727
Info
EMC DiskXtender Hard Coded Authentication Credentials Vulnerability
| Bugtraq ID: | 28727 |
| Class: | Design Error |
| CVE: |
CVE-2008-0961 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2008 12:00AM |
| Updated: | Apr 16 2008 12:29AM |
| Credit: | Stephen Fewer of Harmony Security |
| Vulnerable: |
EMC DiskXtender 6.20.60 |
| Not Vulnerable: | |
Discussion
EMC DiskXtender Hard Coded Authentication Credentials Vulnerability
DiskXtender is prone to a security vulnerability because its authentication routines contain hard-coded authentication credentials.
Attackers can leverage this issue to gain unauthorized access and compromise the affected DiskXtender servers.
DiskXtender 6.20.060 for Windows is vulnerable; other versions may also be affected.
DiskXtender is prone to a security vulnerability because its authentication routines contain hard-coded authentication credentials.
Attackers can leverage this issue to gain unauthorized access and compromise the affected DiskXtender servers.
DiskXtender 6.20.060 for Windows is vulnerable; other versions may also be affected.
Exploit / POC
EMC DiskXtender Hard Coded Authentication Credentials Vulnerability
Attackers can exploit this issue by learning the hard-coded credentials and connecting to an affected server via the RPC interface.
Attackers can exploit this issue by learning the hard-coded credentials and connecting to an affected server via the RPC interface.
Solution / Fix
EMC DiskXtender Hard Coded Authentication Credentials Vulnerability
Solution:
The vendor released updates to address this issue. Please contact the vendor for information on how to obtain and apply the fixes.
Solution:
The vendor released updates to address this issue. Please contact the vendor for information on how to obtain and apply the fixes.