CVE-2017-4984
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able to elevate their permissions to root through a command injection. This may potentially be exploited by an attacker to run arbitrary code with root-level privileges on the targeted VNX Control Station system, aka remote code execution.
En EMC VNX2 en versiones anteriores a OE for File 8.1.9.211 y VNX1 en versiones anteriores a OE for File 7.1.80.8, un atacante remoto no autenticado podría ser capaz de elevar sus privilegios a root mediante una inyección de comandos. Esto podría ser explotado por un atacante para ejecutar código arbitrario con privilegios de nivel root en el sistema VNX Control Station objetivo. Esto también se conoce como ejecución remota de código.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-29 CVE Reserved
- 2017-06-16 CVE Published
- 2024-01-21 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/540738/30/0/threaded | Third Party Advisory | |
http://www.securityfocus.com/bid/99039 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Vnx2 Firmware Search vendor "Emc" for product "Vnx2 Firmware" | - | - |
Affected
| in | Emc Search vendor "Emc" | Vnx2 Search vendor "Emc" for product "Vnx2" | - | - |
Safe
|
Emc Search vendor "Emc" | Vnx1 Firmware Search vendor "Emc" for product "Vnx1 Firmware" | - | - |
Affected
| in | Emc Search vendor "Emc" | Vnx1 Search vendor "Emc" for product "Vnx1" | - | - |
Safe
|