CVE Vulnerabilities

CVE-2017-2768

Improper Authentication

Published: Feb 03, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains an Improper Authentication vulnerability that could potentially be exploited by malicious users to compromise the affected system.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Smarts_network_configuration_managerEmc9.3 (including)9.3 (including)
Smarts_network_configuration_managerEmc9.4 (including)9.4 (including)
Smarts_network_configuration_managerEmc9.4.1 (including)9.4.1 (including)
Smarts_network_configuration_managerEmc9.4.2 (including)9.4.2 (including)

Potential Mitigations

References