Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple configuration files with world-readable permissions that could allow an authenticated malicious user to utilize the file contents to potentially elevate their privileges.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://seclists.org/fulldisclosure/2018/Oct/35 | third party advisory mailing list |
http://www.securityfocus.com/bid/105694 | vdb entry third party advisory |
http://www.securitytracker.com/id/1041877 | vdb entry third party advisory |