The SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center before 6.1 does not properly authenticate SST_SENDFILE requests, which allows remote attackers to read arbitrary files. http://secunia.com/advisories/32801
Apply Patches:
EMC ControlCenter v 5.x:
Update to version 5.2 SP5 Patch 4433.
EMC ControlCenter v 6.x:
Update to version 6.0 Patch 4434.
Publication date: Wed, 10 Dec 2008 20:00:00 +0000