EMC vuln gives mere sysadmins the power of storage admins
EMC has warned a flaw in the Control Station software for its VNX and Celerra arrays could allow just about anyone logged into them to do just about anything.
EMC's described the fault as stemming from “Script files in affected products exist with ownership permissions for the nasadmin group account.”
The nasadmin group is designed as a group of general users, while the user with the same name “has system-wide management capabilities for the box and is authorized to make extensive changes to the storage system.” The flaw means folks in the group get the same privileges as nasdmin, the user.