CVE-2017-8023
Estado: ModificadaCrítica (9.8)—
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrexecd) when oldauth authentication method is used. An unauthenticated remote attacker could send arbitrary commands via RPC service to be executed on the host system with the privileges of the nsrexecd service, which runs with administrative privileges.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.88%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-8023",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "security_alert@emc.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "Dell EMC",
"product": "Networker",
"versions": [
{
"status": "affected",
"version": "8.2.X"
},
{
"status": "affected",
"version": "9.0.X"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "9.1.15",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "9.2.1",
"versionType": "custom"
}
]
}
]
}
],
"published": "2019-04-01T21:29:24.263",
"references": [
{
"url": "http://www.securityfocus.com/bid/107712",
"source": "security_alert@emc.com"
},
{
"url": "https://seclists.org/fulldisclosure/2019/Mar/50",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "security_alert@emc.com"
},
{
"url": "http://www.securityfocus.com/bid/107712",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://seclists.org/fulldisclosure/2019/Mar/50",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrexecd) when oldauth authentication method is used. An unauthenticated remote attacker could send arbitrary commands via RPC service to be executed on the host system with the privileges of the nsrexecd service, which runs with administrative privileges."
},
{
"lang": "es",
"value": "EMC NetWorker, podría ser vulnerable a una ejecución remota de código sin autenticar en el servicio de ejecución \"Networker Client\" (nsrexecd) cuando se utiliza el método de autenticación \"oldauth\". Un atacante remoto no autenticado podría enviar comandos arbitrarios mediante un servicio RPC que se ejecutará en el sistema host con los privilegios del servicio \"nsrexecd\", que se ejecuta con privilegios de administrador."
}
],
"lastModified": "2026-06-17T01:25:39.373",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:dell:emc_networker:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA8B675E-2B3D-42BF-9BB1-17E0987D74C9",
"versionEndExcluding": "8.2.4.11",
"versionStartIncluding": "8.2.0.0"
},
{
"criteria": "cpe:2.3:a:dell:emc_networker:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4FF5DC2D-86B4-4470-A855-B078DEE0DA06",
"versionEndIncluding": "9.0.1.9",
"versionStartIncluding": "9.0.0.0"
},
{
"criteria": "cpe:2.3:a:dell:emc_networker:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72A5D229-468B-4DEA-8D53-857675175A23",
"versionEndExcluding": "9.1.1.5",
"versionStartIncluding": "9.1.0.0"
},
{
"criteria": "cpe:2.3:a:dell:emc_networker:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B9576971-C495-4FCF-BEE1-52860CFFD803",
"versionEndExcluding": "9.2.1.0",
"versionStartIncluding": "9.2.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security_alert@emc.com"
}