EMC AlphaStor Format String and Command Injection Vulnerabilities
BID:57472
Info
EMC AlphaStor Format String and Command Injection Vulnerabilities
| Bugtraq ID: | 57472 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0928 CVE-2013-0929 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2013 12:00AM |
| Updated: | Sep 30 2014 01:00AM |
| Credit: | [email protected] |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
EMC AlphaStor Format String and Command Injection Vulnerabilities
EMC AlphaStor is prone to a format-string vulnerability and a remote command-injection vulnerability.
An attacker can exploit these issues to execute arbitrary code. Failed exploit attempts will likely result in a denial-of-service condition.
EMC AlphaStor versions prior 4.0 Build 800 are vulnerable.
EMC AlphaStor is prone to a format-string vulnerability and a remote command-injection vulnerability.
An attacker can exploit these issues to execute arbitrary code. Failed exploit attempts will likely result in a denial-of-service condition.
EMC AlphaStor versions prior 4.0 Build 800 are vulnerable.
Exploit / POC
EMC AlphaStor Format String and Command Injection Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
EMC AlphaStor Format String and Command Injection Vulnerabilities
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
EMC AlphaStor Format String and Command Injection Vulnerabilities
References:
References:
- EMC AlphaStor Homepage (EMC)