Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

EMC Patches Critical Flaws in VMAX Storage Products

Researchers at vulnerability management services provider Digital Defense have identified a total of six flaws in the administration interface of EMC VMAX enterprise storage products.

Researchers at vulnerability management services provider Digital Defense have identified a total of six flaws in the administration interface of EMC VMAX enterprise storage products.

EMC VMAX is an enterprise storage solution designed for storage area network (SAN) environments. The vulnerabilities found by Digital Defense affect versions 8.0.x through 8.2.x of the VMAX Unisphere web-based management console and the vApp Manager configuration and support tool for VMware deployments. EMC has released patches that address the security holes.

Of the six vulnerabilities, two have been rated critical, while the rest are high severity. The list includes arbitrary file retrieval, denial-of-service (DoS) and command execution issues.

One of the critical flaws is related to vApp Manager’s use of the Action Message Format (AMF) for server communications. While the RemoteServiceHandler class verifies certain types of AMF messages, some types are not validated properly, allowing an attacker to bypass authentication and gain root privileges on the system.

The attacker can exploit this vulnerability to add new admin users and completely compromise the virtual appliance.

The second critical security hole is related to vApp Manager’s use of GetSymmCmdRequest AMF messages. An unauthenticated attacker can execute arbitrary commands with root privileges and hijack the targeted appliance via specially crafted AMF messages.

Advertisement. Scroll to continue reading.

A similar vulnerability, involving GeneralCmdRequest messages, requires an attacker to authenticate on the system before executing arbitrary commands with root privileges. However, researchers pointed out that they can achieve this by leveraging the first flaw to create a new admin account.

Digital Defense warned that similar attacks can also be carried out via specially crafted GetCommandExecRequest and PersistantDataRequest AMF messages.

An XML External Entity (XXE) flaw found by experts in the Unisphere interface allows unauthenticated attackers to retrieve arbitrary text files from the virtual appliance. The same weakness (CVE-2016-2340) can also be leveraged to cause a DoS condition.

Related: Dell Finalizes Huge EMC Deal to Become Tech Titan

Related: LG NAS Devices Exposed to Remote Attacks

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.