Vulnerability Note VU#913483
Quantum Scalar i500, Dell ML6000 and IBM TS3310 tape libraries web interface and preconfigured password vulnerabilities
Overview
Cross scripting and preconfigured password vulnerabilities have been reported to exist in the Quantum Scalar i500, Dell ML6000 and IBM TS3310 tape libraries.
Description
Quantum Scalar i500, Dell ML6000 and IBM TS3310 enterprise tape libraries contain multiple web interface and preconfigured account password vulnerabilities. The Quantum Scalar i500 and Dell ML6000 tape libraries contain the following web interface vulnerabilities.
The CVSS metrics below apply to CVE-2012-1844. |
Impact
An attacker with access to a local user account or via malicious URL can execute arbitrary code or commands on the vulnerable system. It has been reported to us that customer data residing on the tapes within the libraries are not affected. |
Solution
Upgrade firmware |
Restrict access |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Dell Computer Corporation, Inc. | Affected | 16 Nov 2011 | 02 Mar 2012 |
| IBM Corporation | Affected | 23 Nov 2011 | 02 Mar 2012 |
| Quantum | Affected | 23 Nov 2011 | 02 Mar 2012 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| Temporal | 5.3 | E:POC/RL:OF/RC:C |
| Environmental | 5.3 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://cwe.mitre.org/data/definitions/552.html
- http://cwe.mitre.org/data/definitions/200.html
- http://cwe.mitre.org/data/definitions/352.html
- http://cwe.mitre.org/data/definitions/259.html
- http://www.quantum.com/ServiceandSupport/SoftwareandDocumentationDownloads/SI500/Index.aspx
- http://support.dell.com
- http://www-933.ibm.com/support/fixcentral/
Credit
Thanks to NOAA CIRT for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2012-1844 CVE-2012-1843 CVE-2012-1842 CVE-2012-1841
- Date Public: 19 Mar 2012
- Date First Published: 19 Mar 2012
- Date Last Updated: 13 Apr 2012
- Document Revision: 41
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.