CVE-2008-2157
EMC AlphaStor Device Manager Arbitrary Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
robotd in the Library Manager in EMC AlphaStor 3.1 SP1 for Windows allows remote attackers to execute arbitrary commands via an unspecified string field in a packet to TCP port 3500.
robotd en la Library Manager de EMC AlphaStor 3.1 SP1 para Windows, permite a atacantes remotos ejecutar comandos de su elección mediante un campo de cadena no especificado en un paquete al puerto TCP 3500.
Remote exploitation of an arbitrary command execution vulnerability in EMC Corp.'s AlphaStor could allow an attacker to execute arbitrary code with SYSTEM privileges. AlphaStor consists of multiple applications, one of which is the Library Manager. The Library Manager is used to manage the replacement of disk drives in distributed locations. The Manager consists of a single process, the "robotd" process, that listens on TCP port 3500 for incoming connections. The Library Manager is prone to an arbitrary command execution vulnerability. When sent a specific request, "robotd" will use a string from the packet as a command to execute on the system via the CreateProcess() function. This allows an attacker to run arbitrary programs on the host with SYSTEM privileges. iDefense has confirmed the existence of this vulnerability in AlphaStor version 3.1 SP1 for Windows. Previous versions, as well as versions for other platforms, may also be affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-05-12 CVE Reserved
- 2008-05-27 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-31 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=703 | Third Party Advisory | |
http://securitytracker.com/id?1020116 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1670 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42671 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/180816 | 2024-08-31 | |
https://packetstorm.news/files/id/180815 | 2024-08-31 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/30410 | 2017-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Corporation Search vendor "Emc Corporation" | Alphastor Search vendor "Emc Corporation" for product "Alphastor" | 3.1_sp1 Search vendor "Emc Corporation" for product "Alphastor" and version "3.1_sp1" | - |
Affected
|