CVE Vulnerabilities

CVE-2017-8023

Improper Authentication

Published: Apr 01, 2019 | Modified: Apr 04, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrexecd) when oldauth authentication method is used. An unauthenticated remote attacker could send arbitrary commands via RPC service to be executed on the host system with the privileges of the nsrexecd service, which runs with administrative privileges.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Emc_networker Dell 8.2.0.0 (including) 8.2.4.11 (excluding)
Emc_networker Dell 9.0.0.0 (including) 9.0.1.9 (including)
Emc_networker Dell 9.1.0.0 (including) 9.1.1.5 (excluding)
Emc_networker Dell 9.2.0.0 (including) 9.2.1.0 (excluding)

Potential Mitigations

References