vendor:
AlphaStor
by:
Anyway, Preston Thornburn, Mohsan Farid, Brent Morris, juan vazquez
N/A
CVSS
N/A
Command Injection
78
CWE
Product Name: AlphaStor
Affected Version From: EMC AlphaStor 4.0 < build 800
Affected Version To: EMC AlphaStor 4.0 < build 800
Patch Exists: NO
Related CWE: CVE-2013-0928, ZDI-13-033
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Universal
2013
EMC AlphaStor Device Manager Opcode 0x75 Command Injection
This module exploits a flaw within the Device Manager (rrobtd.exe). When parsing the 0x75 command, the process does not properly filter user supplied input allowing for arbitrary command injection. This module has been tested successfully on EMC AlphaStor 4.0 build 116 with Windows 2003 SP2 and Windows 2008 R2.
Mitigation:
No known mitigation or remediation for this vulnerability