CVE-2011-0321

EMC NetWorker < 7.5 - Denial of Service via Spoofed Localhost UDP Packets

Title source: llm
STIX 2.1

Description

librpc.dll in nsrexecd in EMC NetWorker before 7.5 SP4, 7.5.3.x before 7.5.3.5, and 7.6.x before 7.6.1.2 does not properly mitigate the possibility of a spoofed localhost source IP address, which allows remote attackers to (1) register or (2) unregister RPC services, and consequently cause a denial of service or obtain sensitive information from interprocess communication, via crafted UDP packets containing service commands.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1025010
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46044
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64997
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2011-01/0162.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/70686
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43113
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0241

Scores

EPSS 0.0165
EPSS Percentile 82.2%

Details

CWE
CWE-264
Status published
Products (21)
emc/networker 6.0
emc/networker 6.1
emc/networker 7.0
emc/networker 7.2
emc/networker 7.3
emc/networker 7.4 (6 CPE variants)
emc/networker 7.5 (3 CPE variants)
emc/networker 7.5.3.1
emc/networker 7.5.3.2
emc/networker 7.5.3.3
... and 11 more
Published Feb 01, 2011
Tracked Since Feb 18, 2026