CVE-2008-2157

EMC Corporation Alphastor - Improper Input Validation

Title source: rule

Description

robotd in the Library Manager in EMC AlphaStor 3.1 SP1 for Windows allows remote attackers to execute arbitrary commands via an unspecified string field in a packet to TCP port 3500.

Exploits (2)

metasploit WORKING POC
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/emc/alphastor_devicemanager_exec.rb
metasploit WORKING POC
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/emc/alphastor_librarymanager_exec.rb

Scores

EPSS 0.8500
EPSS Percentile 99.3%

Classification

CWE
CWE-20
Status draft

Affected Products (1)

emc_corporation/alphastor

Timeline

Published May 29, 2008
Tracked Since Feb 18, 2026