EMC
EMC Networker: vulnerabilidades y CVE
EMC Networker tiene 20 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-15550 | Alta (8.8) | 8.2% | — | 5 ene 2018 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious… |
| CVE-2017-15549 | Alta (8.8) | 5.5% | — | 5 ene 2018 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious… |
| CVE-2017-15548 | Crítica (9.8) | 4.7% | — | 5 ene 2018 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated… |
| CVE-2017-8022 | Alta (8.1) | 3.2% | — | 18 oct 2017 | An issue was discovered in EMC NetWorker (prior to 8.2.4.9, all supported 9.0.x versions, prior to 9.1.1.3, prior to 9.2.0.4). The Server service (nsrd) is affected by a buffer overflow vulnerability. A remote… |
| CVE-2016-0916 | Crítica (9.8) | 7.7% | — | 10 jun 2016 | EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance. |
| CVE-2015-6849 | Alta (7.8) | 2.3% | — | 5 dic 2015 | EMC NetWorker before 8.0.4.5, 8.1.x before 8.1.3.6, 8.2.x before 8.2.2.2, and 9.0 before build 407 allows remote attackers to cause a denial of service (process outage) via malformed RPC authentication messages. |
| CVE-2015-0530 | Alta (7.2) | 0.40% | — | 17 abr 2015 | Buffer overflow in an unspecified function in nsr_render_log in EMC NetWorker before 8.0.4.3, 8.1.x before 8.1.2.6, and 8.2.x before 8.2.1.2 allows local users to gain privileges via unknown vectors. |
| CVE-2014-4620 | Baja (2.1) | 0.53% | — | 25 oct 2014 | The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local… |
| CVE-2013-3285 | Baja (3.5) | 1.00% | — | 2 nov 2013 | The NetWorker Management Console (NMC) in EMC NetWorker 8.0.x before 8.0.2.3, when using Active Directory/LDAP for authentication, allows remote authenticated users to discover cleartext administrator passwords via (1)… |
| CVE-2013-0943 | Media (4.6) | 0.30% | — | 31 jul 2013 | EMC NetWorker 7.6.x and 8.x before 8.1 allows local users to obtain sensitive configuration information by leveraging operating-system privileges to perform decryption with nsradmin. |
| CVE-2013-0940 | Alta (7.2) | 0.39% | — | 3 may 2013 | The nsrpush process in the client in EMC NetWorker before 7.6.5.3 and 8.x before 8.0.1.4 sets weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. |
| CVE-2012-4607 | Alta (9.3) | 3.2% | — | 17 ene 2013 | Buffer overflow in nsrindexd in EMC NetWorker 7.5.x and 7.6.x before 7.6.5, and 8.x before 8.0.0.6, allows remote attackers to execute arbitrary code via crafted SunRPC data. |
| CVE-2012-2288 | Alta (9.3) | 33% | — | 4 sept 2012 | Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via format string specifiers in a message. |
| CVE-2012-0395 | Alta (9.3) | 3.0% | — | 27 ene 2012 | Buffer overflow in the server in EMC NetWorker 7.5.x and 7.6.x before 7.6.3 SP1 Cumulative Release build 851 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via… |
| CVE-2011-1421 | Media (6.9) | 0.31% | — | 22 abr 2011 | EMC NetWorker 7.5.x before 7.5.4.3 and 7.6.x before 7.6.1.5, when the client push feature is enabled, uses weak permissions for an unspecified file, which allows local users to gain privileges via unknown vectors. |
| CVE-2011-0321 | Media (6.4) | 2.6% | — | 1 feb 2011 | librpc.dll in nsrexecd in EMC NetWorker before 7.5 SP4, 7.5.3.x before 7.5.3.5, and 7.6.x before 7.6.1.2 does not properly mitigate the possibility of a spoofed localhost source IP address, which allows remote attackers… |
| CVE-2006-3892 | Alta (10) | 4.6% | — | 2 mar 2007 | The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote attackers to execute arbitrary commands. |
| CVE-2002-0113 | Media (4.6) | 0.37% | — | 25 mar 2002 | EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges.… |
| CVE-2002-0114 | Media (4.6) | 0.37% | — | 25 mar 2002 | EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file. NOTE: this was originally… |
| CVE-2001-0910 | Alta (7.5) | 2.4% | — | 21 nov 2001 | Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP… |
Otros productos de EMC
RSA Authentication Manager · 25RSA Archer Egrc · 23Documentum Content Server · 21Isilon Onefs · 15Avamar Server · 13Documentum Webtop · 13Documentum D2 · 12Documentum Taskspace · 12RSA Identity Management AND Governance · 11Documentum Administrator · 10RSA Adaptive Authentication On-premise · 10Documentum WDK · 10