CVE-2018-1238 Information
Feb 14, 2021
cve
Description
Dell EMC ScaleIO versions prior to 2.5 contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for central management of ScaleIO deployment and uses shell commands for certain actions. A remote malicious user with network access to LIA and knowledge of the LIA administrative password could potentially exploit this vulnerability to run arbitrary commands as root on the systems where LIAs are installed.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
http://seclists.org/fulldisclosure/2018/Mar/59
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.5
Share on: