Vulnerability Name: | CVE-2018-1238 (CCN-140842) | ||||||||||||
Assigned: | 2017-12-06 | ||||||||||||
Published: | 2018-03-26 | ||||||||||||
Updated: | 2020-08-24 | ||||||||||||
Summary: | Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for central management of ScaleIO deployment and uses shell commands for certain actions. A remote malicious user, with network access to LIA and knowledge of the LIA administrative password, could potentially exploit this vulnerability to run arbitrary commands as root on the systems where LIAs are installed. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 8.5 High (CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-78 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-1238 Source: CCN Type: Dell EMC Identifier: DSA-2018-058 Dell EMC ScaleIO Multiple Security Vulnerabilities Source: FULLDISC Type: Mailing List, Third Party Advisory 20180326 DSA-2018-058: Dell EMC ScaleIO Multiple Security Vulnerabilities Source: XF Type: UNKNOWN emc-scaleio-cve20181238-cmd-exec(140842) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |