Dell PowerVault ML6000 and Quantum Scalar i500 CVE-2014-2959 Remote Command Injection Vulnerability
BID:67751
Info
Dell PowerVault ML6000 and Quantum Scalar i500 CVE-2014-2959 Remote Command Injection Vulnerability
| Bugtraq ID: | 67751 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2959 |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2014 12:00AM |
| Updated: | May 30 2014 12:00AM |
| Credit: | Benjamin Buchanan |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Dell PowerVault ML6000 and Quantum Scalar i500 CVE-2014-2959 Remote Command Injection Vulnerability
Dell PowerVault ML6000 and Quantum Scalar i500 are prone to a remote command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands in the context of the affected device.
The following products are vulnerable:
Quantum Scalar i500 firmware versions i8.2.2 (645G.GS004) and prior
Dell PowerVault ML6000 firmware version i8.2.0.1 (641G.GS003) and prior
Dell PowerVault ML6000 and Quantum Scalar i500 are prone to a remote command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands in the context of the affected device.
The following products are vulnerable:
Quantum Scalar i500 firmware versions i8.2.2 (645G.GS004) and prior
Dell PowerVault ML6000 firmware version i8.2.0.1 (641G.GS003) and prior
Exploit / POC
Dell PowerVault ML6000 and Quantum Scalar i500 CVE-2014-2959 Remote Command Injection Vulnerability
Attackers can exploit this issue using browser or readily available tools.
Attackers can exploit this issue using browser or readily available tools.
Solution / Fix
Dell PowerVault ML6000 and Quantum Scalar i500 CVE-2014-2959 Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.