Skip to main content

EMC vuln gives mere sysadmins the power of storage admins

posted onMay 20, 2013
by l33tdawg

EMC has warned a flaw in the Control Station software for its VNX and Celerra arrays could allow just about anyone logged into them to do just about anything.

EMC's described the fault as stemming from “Script files in affected products exist with ownership permissions for the nasadmin group account.”

The nasadmin group is designed as a group of general users, while the user with the same name “has system-wide management capabilities for the box and is authorized to make extensive changes to the storage system.” The flaw means folks in the group get the same privileges as nasdmin, the user.

Source

Tags

EMC Security

You May Also Like

Recent News

Friday, April 20th

Wednesday, April 11th

Tuesday, April 10th

Monday, April 9th

Saturday, April 7th

Friday, April 6th

Thursday, April 5th

Wednesday, April 4th