CVE-2018-1215 is an arbitrary file upload vulnerability in the vApp Manager component of several Dell EMC products, including Unisphere for VMAX, Solutions Enabler, VASA Virtual Appliances, and VMAX Embedded Management. This vulnerability allows an authenticated remote attacker to upload malicious files to any location on the web server. With a CVSS score of 8.8 (High), it poses a significant risk of full compromise (confidentiality, integrity, availability) if exploited. While no public exploit code or active exploitation has been reported, its chaining with CVE-2018-1216 using default accounts increases its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.4.0.21CPE matchmatch criteria | cpe:2.3:a:dell:emc_solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:* | ||
< 8.4.0.18CPE matchmatch criteria | cpe:2.3:a:dell:emc_unisphere_for_vmax_virtual_appliance:*:*:*:*:*:*:*:* | ||
< 8.4.0.514CPE matchmatch criteria | cpe:2.3:a:dell:emc_vasa_virtual_appliance:*:*:*:*:*:*:*:* | ||
<= 1.4CPE matchmatch criteria | cpe:2.3:a:dell:emc_vmax_embedded_management:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R2] EMC VASA Virtual Appliance Default Creds and Arbitrary File Upload
Feb 15, 2018[R2] EMC VASA Virtual Appliance Default Creds and Arbitrary File Upload
Feb 15, 2018EMC VASA Virtual Appliance Default Creds and Arbitrary File Upload
Feb 15, 2018