Release date:
Updated on:
Affected Systems:
NEC Universal RAID Utility
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58087
CVE (CAN) ID: CVE-2013-0706
Universal RAID Utility is a software for managing RAID controllers.
The NEC Universal RAID Utility does not have access restrictions and allows remote attackers to perform any RAID disk operations through TCP port 52805.
<* Source: SAKURA Internet Inc
Link: http://www.securelist.com/en/advisories/52241
Http://jvndb.jvn.jp/en/contents/2013/JVNDB-2013-000012.html
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat:
* Restrict access from 4984/TCP.
Vendor patch:
NEC
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.nec.com.sg/index.php? Q = products/enterprise-servers