### [CVE-2018-1250](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1250) ![](https://img.shields.io/static/v1?label=Product&message=Dell%20EMC%20Unity&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Dell%20EMC%20UnityVSA&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Authorization%20Bypass&color=brighgreen) ### Description Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing Role-Based Authorization control implemented only in Unisphere GUI. ### POC #### Reference - https://seclists.org/fulldisclosure/2018/Sep/30 - https://seclists.org/fulldisclosure/2018/Sep/30 #### Github No PoCs found on GitHub currently.