ASA-2018-00017 – Dell EMC Integrated Data Protection Appliance: Undocumented Accounts Vulnerability


Allele Security Alert

ASA-2018-00017

Identifier(s)

ASA-2018-00017, CVE-2018-11062, DSA-2018-136

Title

Dell EMC Integrated Data Protection Appliance Undocumented Accounts Vulnerability

Vendor(s)

Dell

Product(s)

Dell EMC Integrated Data Protection Appliance

Affected version(s)

Dell EMC Integrated Data Protection Appliance 2.0

Dell EMC Integrated Data Protection Appliance 2.1

Dell EMC Integrated Data Protection Appliance 2.2

Fixed version(s)

Dell EMC Integrated Data Protection Appliance 2.1.0.599285

Proof of concept

Unknown

Description

Integrated Data Protection Appliance (iDPA) contains undocumented accounts with limited access which may potentially be used by a malicious user to compromise the affected system.

Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named “support” and “admin” that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may potentially log in to the system and gain read and write access to certain system files.

Technical details

Unknown

Reference(s)

DSA-2018-136: Dell EMC Integrated Data Protection Appliance Undocumented Accounts Vulnerability
https://seclists.org/fulldisclosure/2018/Oct/53

Dell EMC Knowledgebase article 468307
https://support.emc.com/kb/468307

CVE-2018-11062
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11062

CVE-2018-11062
https://nvd.nist.gov/vuln/detail/CVE-2018-11062

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: February 1, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.