CVE-2017-2767

CRITICAL

EMC Network Configuration Manager 9.3.x-9.4.2.x - Remote Code Execution via Java RMI

Title source: llm
STIX 2.1

Description

EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains a Java RMI Remote Code Execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95938
Mailing List, Third Party Advisory, VDB Entry x_refsource_confirm
http://www.securityfocus.com/archive/1/540085/30/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037761

Scores

CVSS v3 9.8
EPSS 0.1075
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (5)
emc/smarts_network_configuration_manager 9.3
emc/smarts_network_configuration_manager 9.4
emc/smarts_network_configuration_manager 9.4.1
emc/smarts_network_configuration_manager 9.4.2
n/a/EMC Network Configuration Manager EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configura EMC Network Configuration Manager EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configu
Published Feb 03, 2017
Tracked Since Feb 18, 2026