CVE-2017-4984
CRITICALEMC VNX2 <8.1.9.211 & VNX1 <7.1.80.8 - Command Injection
Title source: llmDescription
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able to elevate their permissions to root through a command injection. This may potentially be exploited by an attacker to run arbitrary code with root-level privileges on the targeted VNX Control Station system, aka remote code execution.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry x_refsource_confirm
http://www.securityfocus.com/archive/1/540738/30/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/99039
Scores
CVSS v3
9.8
EPSS
0.0351
EPSS Percentile
87.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-77
Status
published
Products (3)
emc/vnx1_firmware
emc/vnx2_firmware
n/a/EMC VNX2 versions prior to OE for File 8.1.9.211, EMC VNX1 versions prior to OE for File 7.1.80.8
EMC VNX2 versions prior to OE for File 8.1.9.211, EMC VNX1 versions prior to OE for File 7.1.80.8
Published
Jun 19, 2017
Tracked Since
Feb 18, 2026