CVE-2016-6646

CRITICAL

EMC Unisphere for VMAX Virtual Appliance <8.3.0 - RCE

Title source: llm
STIX 2.1

Description

The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input to the (1) GetSymmCmdRequest or (2) RemoteServiceHandler class.

References (3)

Core 3
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://seclists.org/bugtraq/2016/Oct/7
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036941
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93343

Scores

CVSS v3 9.8
EPSS 0.0393
EPSS Percentile 88.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (10)
dell/emc_unisphere 8.0
dell/emc_unisphere 8.1
dell/emc_unisphere 8.1.2
dell/emc_unisphere 8.2
emc/solutions_enabler 8.0
emc/solutions_enabler 8.0.3
emc/solutions_enabler 8.1
emc/solutions_enabler 8.1.2
emc/solutions_enabler 8.3
emc/unisphere 8.0.3
Published Oct 05, 2016
Tracked Since Feb 18, 2026