Authorization Bypass in Dell EMC Unity and UnityVSA Products
CVE-2018-1250
6.5MEDIUM
What is CVE-2018-1250?
Dell EMC Unity and UnityVSA versions before 4.3.1.1525703027 are affected by an authorization bypass issue that permits remote authenticated users to exploit certain APIs of Unity OE. This vulnerability enables unauthorized file access on NAS servers by circumventing the Role-Based Authorization system enforced solely within the Unisphere GUI. Thus, it poses a significant risk in terms of data exposure.
Affected Version(s)
Dell EMC Unity < 4.3.1.1525703027
Dell EMC UnityVSA < 4.3.1.1525703027