# N/A
## 漏洞概述
Dell EMC Avamar Server 和 Integrated Data Protection Appliance 中的 Avamar Installation Manager 存在访问控制检查缺失的漏洞,可能允许远程未认证攻击者读取或更改 Local Download Service (LDLS) 凭证。
## 影响版本
- Dell EMC Avamar Server 7.3.1
- Dell EMC Avamar Server 7.4.1
- Dell EMC Avamar Server 7.5.0
- Dell EMC Integrated Data Protection Appliance 2.0
- Dell EMC Integrated Data Protection Appliance 2.1
## 细节
Avamar Installation Manager 中缺少对 LDLS 凭证的访问控制检查。该漏洞允许远程未认证攻击者读取或更改用于连接 Dell EMC Online Support 的 LDLS 凭证。如果 LDLS 配置被修改为无效配置,Avamar Installation Manager 可能无法成功连接到 Dell EMC Online Support 网站。
## 影响
远程未认证攻击者可以读取并使用凭证登录 Dell EMC Online Support,并通过这些凭证冒充 AVI 服务的行为。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-1217.yaml | POC详情 |
暂无评论