Allele Security Alert
ASA-2018-00017
Identifier(s)
ASA-2018-00017, CVE-2018-11062, DSA-2018-136
Title
Dell EMC Integrated Data Protection Appliance Undocumented Accounts Vulnerability
Vendor(s)
Dell
Product(s)
Dell EMC Integrated Data Protection Appliance
Affected version(s)
Dell EMC Integrated Data Protection Appliance 2.0
Dell EMC Integrated Data Protection Appliance 2.1
Dell EMC Integrated Data Protection Appliance 2.2
Fixed version(s)
Dell EMC Integrated Data Protection Appliance 2.1.0.599285
Proof of concept
Unknown
Description
Integrated Data Protection Appliance (iDPA) contains undocumented accounts with limited access which may potentially be used by a malicious user to compromise the affected system.
Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named “support” and “admin” that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may potentially log in to the system and gain read and write access to certain system files.
Technical details
Unknown
Reference(s)
DSA-2018-136: Dell EMC Integrated Data Protection Appliance Undocumented Accounts Vulnerability
https://seclists.org/fulldisclosure/2018/Oct/53
Dell EMC Knowledgebase article 468307
https://support.emc.com/kb/468307
CVE-2018-11062
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11062
CVE-2018-11062
https://nvd.nist.gov/vuln/detail/CVE-2018-11062
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: February 1, 2019