← back
CVE-2019-18580criticalCWE-502

CVE-2019-18580

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 4.9%
exploitation probability
4.9%top 9% of all CVEs
observed exploitation
nono source reports it
In short

Dell EMC Storage Monitoring and Reporting 4.3.1 has a flaw that allows attackers to send specially crafted messages over the network to run malicious code on the server without needing a password. This is dangerous because an attacker anywhere on the internet can take complete control of the system.

Technical detail

The vulnerability exists in Java RMI deserialization of untrusted data (CWE-502). An unauthenticated remote attacker can send a crafted RMI request that causes unsafe deserialization, leading to arbitrary code execution on the target host. The attack vector is network-based with no authentication or user interaction required, resulting in critical confidentiality, integrity, and availability impact.

Summary generated and translated by AI from the official description.
Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Dell · EMC Storage M&R