← Back

CVE-2012-1843

nvd nist
Published: Mar 22, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in saveRestore.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to hijack the authentication of users for requests that execute Linux commands via the fileName parameter, related to a "command-injection vulnerability."

Affected (22)

2 products
Scalar I500 Firmware
Scalar I500
5 products
Powervault Ml6000 Firmware
Powervault Ml6000
Powervault Ml6010
Powervault Ml6020
Powervault Ml6030
Configuration A
16 vulnerable
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Version 585g.gs003
Dell
Version 32u
Version 41u
Version 5u
Version 14u
Version 23u

References (14)

Source: cve@mitre.org
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.