CVE-2016-6645

HIGH

EMC Unisphere for VMAX Virtual Appliance <8.3.0 - Authenticated RCE

Title source: llm
STIX 2.1

Description

The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote authenticated users to execute arbitrary code via crafted input to the (1) GeneralCmdRequest, (2) PersistantDataRequest, or (3) GetCommandExecRequest class.

References (3)

Core 3
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://seclists.org/bugtraq/2016/Oct/7
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036941
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93343

Scores

CVSS v3 8.8
EPSS 0.0134
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (10)
dell/emc_unisphere 8.0
dell/emc_unisphere 8.1
dell/emc_unisphere 8.1.2
dell/emc_unisphere 8.2
emc/solutions_enabler 8.0
emc/solutions_enabler 8.0.3
emc/solutions_enabler 8.1
emc/solutions_enabler 8.1.2
emc/solutions_enabler 8.2
emc/unisphere 8.0.3
Published Oct 05, 2016
Tracked Since Feb 18, 2026