The SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center before 6.1 does not properly authenticate SST_SENDFILE requests, which allows remote attackers to read arbitrary files.
| Software | From | Fixed in |
|---|---|---|
| emc / control_center | 5.2-sp5 | 5.2-sp5.x |
| emc / control_center | - | 6.0.x |