CVE Vulnerabilities

CVE-2017-2768

Improper Authentication

Published: Feb 03, 2017 | Modified: Jul 25, 2017
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains an Improper Authentication vulnerability that could potentially be exploited by malicious users to compromise the affected system.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Smarts_network_configuration_manager Emc 9.3 (including) 9.3 (including)
Smarts_network_configuration_manager Emc 9.4 (including) 9.4 (including)
Smarts_network_configuration_manager Emc 9.4.1 (including) 9.4.1 (including)
Smarts_network_configuration_manager Emc 9.4.2 (including) 9.4.2 (including)

Potential Mitigations

References