Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authenticated malicious user could read from VPN configuration files on and potentially author a MITM attack on the VPN traffic.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1041613 | vdb entry third party advisory |
https://seclists.org/fulldisclosure/2018/Sep/10 | third party advisory mailing list |