Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious user with the knowledge of the hard-coded password may login to the system and gain read-only privileges.
| Software | From | Fixed in |
|---|---|---|
| dell / emc_data_protection_advisor | 6.4 | 6.4.x |
| dell / emc_data_protection_advisor | 6.5 | 6.5.x |
| dell / emc_data_protection_advisor | 18.1 | 18.1.x |