一、 漏洞 CVE-2018-1217 基础信息
漏洞信息
                                        # N/A

## 漏洞概述
Dell EMC Avamar Server 和 Integrated Data Protection Appliance 中的 Avamar Installation Manager 存在访问控制检查缺失的漏洞,可能允许远程未认证攻击者读取或更改 Local Download Service (LDLS) 凭证。

## 影响版本
- Dell EMC Avamar Server 7.3.1
- Dell EMC Avamar Server 7.4.1
- Dell EMC Avamar Server 7.5.0
- Dell EMC Integrated Data Protection Appliance 2.0
- Dell EMC Integrated Data Protection Appliance 2.1

## 细节
Avamar Installation Manager 中缺少对 LDLS 凭证的访问控制检查。该漏洞允许远程未认证攻击者读取或更改用于连接 Dell EMC Online Support 的 LDLS 凭证。如果 LDLS 配置被修改为无效配置,Avamar Installation Manager 可能无法成功连接到 Dell EMC Online Support 网站。

## 影响
远程未认证攻击者可以读取并使用凭证登录 Dell EMC Online Support,并通过这些凭证冒充 AVI 服务的行为。
                                        
提示
尽管我们采用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。
神龙会尽力确保数据准确,但也请结合实际情况进行甄别与判断。
神龙祝您一切顺利!
漏洞标题
N/A
来源:美国国家漏洞数据库 NVD
漏洞描述信息
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials.
来源:美国国家漏洞数据库 NVD
CVSS信息
N/A
来源:美国国家漏洞数据库 NVD
漏洞类别
N/A
来源:美国国家漏洞数据库 NVD
漏洞标题
Dell EMC Avamar Server和EMC Integrated Data Protection Appliance Avamar Installation Manager 安全漏洞
来源:中国国家信息安全漏洞库 CNNVD
漏洞描述信息
Dell EMC Avamar Server和EMC Integrated Data Protection Appliance(IDPA)都是美国戴尔(Dell)公司的产品。Dell EMC Avamar Server是一套用于服务器的完全虚拟化的备份和恢复软件。EMC Integrated Data Protection Appliance是一套基于磁盘的备份和恢复解决方案。Avamar Installation Manager是其中的一个Avamar安装管理器。 Dell EMC Avamar Ser
来源:中国国家信息安全漏洞库 CNNVD
CVSS信息
N/A
来源:中国国家信息安全漏洞库 CNNVD
漏洞类别
信任管理问题
来源:中国国家信息安全漏洞库 CNNVD
二、漏洞 CVE-2018-1217 的公开POC
# POC 描述 源链接 神龙链接
1 Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-1217.yaml POC详情
三、漏洞 CVE-2018-1217 的情报信息
四、漏洞 CVE-2018-1217 的评论

暂无评论


发表评论