CVE-2017-2768

CRITICAL

EMC Network Configuration Manager 9.3.x-9.4.2.x - Improper Authentication

Title source: llm
STIX 2.1

Description

EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains an Improper Authentication vulnerability that could potentially be exploited by malicious users to compromise the affected system.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95936
Mailing List, Third Party Advisory, VDB Entry x_refsource_confirm
http://www.securityfocus.com/archive/1/540085/30/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037761

Scores

CVSS v3 9.8
EPSS 0.0201
EPSS Percentile 83.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (5)
emc/smarts_network_configuration_manager 9.3
emc/smarts_network_configuration_manager 9.4
emc/smarts_network_configuration_manager 9.4.1
emc/smarts_network_configuration_manager 9.4.2
n/a/EMC Network Configuration Manager EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configura EMC Network Configuration Manager EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configu
Published Feb 03, 2017
Tracked Since Feb 18, 2026