Total vulnerabilities in the database
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components. A remote attacker with the knowledge of the default password may potentially use these accounts to run arbitrary web service and remote procedure calls on the affected system.
Software | From | Fixed in |
---|---|---|
dell / emc_storage_monitoring_and_reporting | 4.0.2 | 4.0.2.x |
dell / emc_vipr_srm | - | 4.0.2.x |