ZeroHour

CVE-2017-4984

CVSS 3.0
9.8 critical
EPSS
7%p93
Published
()
Modified
Description

In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able to elevate their permissions to root through a command injection. This may potentially be exploited by an attacker to run arbitrary code with root-level privileges on the targeted VNX Control Station system, aka remote code execution.

Vendors
emc
Products
vnx2 firmware, vnx1 firmware
Weakness
CWE-77
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.