Vulnerability CVE-2011-0647


Published: 2011-02-10   Modified: 2012-02-13

Description:
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.

See advisories in our WLB2 database:
Topic
Author
Date
High
EMC Replication Manager Command Execution
Davy Douhine
23.10.2013

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
EMC -> Networker module 
EMC -> Replication manager 

 References:
http://www.securityfocus.com/archive/1/516260
http://www.securityfocus.com/archive/1/516282/100/0/threaded
http://www.securityfocus.com/bid/46235
http://www.vupen.com/english/advisories/2011/0304
http://www.zerodayinitiative.com/advisories/ZDI-11-061/
https://exchange.xforce.ibmcloud.com/vulnerabilities/65205

Copyright 2024, cxsecurity.com

 

Back to Top