DSA-2019-086: Dell EMC Unity Family Multiple Vulnerabilities
Auswirkungen
High
Details
Summary:
Dell EMC Unity contains fixes for multiple security vulnerabilities that may potentially be exploited by malicious users to compromise the affected system.
The components are updated for the following vulnerabilities:
- Improper Authorization Vulnerability
CVE-2019-3734
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Server quotas configuration. A remote authenticated Unisphere Operator may potentially exploit this vulnerability to edit quota configuration of other users.
CVSS v3 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)
- Plain-text Password Storage Vulnerability
CVE-2019-3741
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user s (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the Data Collection bundle may use the exposed password to gain access with the privileges of the compromised user.
CVSS v3 Base Score: 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
The components are updated for the following vulnerabilities:
- Improper Authorization Vulnerability
CVE-2019-3734
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Server quotas configuration. A remote authenticated Unisphere Operator may potentially exploit this vulnerability to edit quota configuration of other users.
CVSS v3 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)
- Plain-text Password Storage Vulnerability
CVE-2019-3741
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user s (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the Data Collection bundle may use the exposed password to gain access with the privileges of the compromised user.
CVSS v3 Base Score: 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Betroffene Produkte und Korrektur
Affected products:
-
Dell EMC Unity Operating Environment (OE) versions prior to 5.0.0.0.5.116
-
Dell EMC UnityVSA Operating Environment (OE) versions prior to 5.0.0.0.5.116
Remediation:
The following Dell EMC Unity releases address these vulnerabilities:
-
Dell EMC Unity Operating Environment (OE) version 5.0.0.0.5.116
-
Dell EMC UnityVSA Operating Environment (OE) versions 5.0.0.0.5.116
Dell EMC recommends all customers upgrade at the earliest opportunity.
Customers can refer to Dell EMC target code information at https://support.emc.com/docu39695_Target_Revisions_and_Adoption_Rates.pdf?language=en_US&language=en_US.
Link to Remedies:
Registered Dell EMC Support customers can download Dell EMC Unity software from the Dell EMC Online Support web site at https://support.emc.com/downloads/39949_Dell-EMC-Unity-Family
Affected products:
-
Dell EMC Unity Operating Environment (OE) versions prior to 5.0.0.0.5.116
-
Dell EMC UnityVSA Operating Environment (OE) versions prior to 5.0.0.0.5.116
Remediation:
The following Dell EMC Unity releases address these vulnerabilities:
-
Dell EMC Unity Operating Environment (OE) version 5.0.0.0.5.116
-
Dell EMC UnityVSA Operating Environment (OE) versions 5.0.0.0.5.116
Dell EMC recommends all customers upgrade at the earliest opportunity.
Customers can refer to Dell EMC target code information at https://support.emc.com/docu39695_Target_Revisions_and_Adoption_Rates.pdf?language=en_US&language=en_US.
Link to Remedies:
Registered Dell EMC Support customers can download Dell EMC Unity software from the Dell EMC Online Support web site at https://support.emc.com/downloads/39949_Dell-EMC-Unity-Family