CVE-2008-2157
EMC Corporation Alphastor - Improper Input Validation
Title source: ruleDescription
robotd in the Library Manager in EMC AlphaStor 3.1 SP1 for Windows allows remote attackers to execute arbitrary commands via an unspecified string field in a packet to TCP port 3500.
Exploits (2)
metasploit
WORKING POC
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/emc/alphastor_devicemanager_exec.rb
metasploit
WORKING POC
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/emc/alphastor_librarymanager_exec.rb
References (5)
Scores
EPSS
0.8500
EPSS Percentile
99.3%
Classification
CWE
CWE-20
Status
draft
Affected Products (1)
emc_corporation/alphastor
Timeline
Published
May 29, 2008
Tracked Since
Feb 18, 2026