Storage vulnerabilities
At the time of writing this book, there were no publicized vulnerabilities for any of the major SAN or NAS vendors specific to the access protocols' Fiber Channel or iSCSI. The following two vulnerabilities are for storage vendor management, listed in the National Vulnerability Database (http://nvd.nist.gov).
A number of the vulnerabilities listed specific to storage center around some form of management and authentication information being sent or stored in clear text:
Note
National Cyber Awareness System
Vulnerability summary for CVE-2013-3278
Original release date: 10/01/2013
Last revised: 10/02/2013
Source: US-CERT/NIST
Overview
EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access