CVE-2018-1237

CRITICAL

Dell EMC ScaleIO < 2.5 - Improper Authentication in Light Installation Agent

Title source: llm
STIX 2.1

Description

Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This component is deployed on every server in the ScaleIO cluster and is used for central management of ScaleIO nodes. A remote malicious user, having network access to LIA, could potentially exploit this vulnerability to launch brute force guessing of user names and passwords of user accounts on the LIA.

References (1)

Core 1
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Mar/59

Scores

CVSS v3 9.8
EPSS 0.0032
EPSS Percentile 55.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
dell/emc_scaleio < 2.5
Published Mar 27, 2018
Tracked Since Feb 18, 2026