CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:N/I:N/A:C
AI Score
Confidence
Low
EPSS
Percentile
89.5%
The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.
Vendor | Product | Version | CPE |
---|---|---|---|
emc | data_protection_advisor | 5.5 | cpe:2.3:a:emc:data_protection_advisor:5.5:*:*:*:*:*:*:* |
emc | data_protection_advisor | 5.5 | cpe:2.3:a:emc:data_protection_advisor:5.5:sp1:*:*:*:*:*:* |
emc | data_protection_advisor | 5.6 | cpe:2.3:a:emc:data_protection_advisor:5.6:*:*:*:*:*:*:* |
emc | data_protection_advisor | 5.6 | cpe:2.3:a:emc:data_protection_advisor:5.6:sp1:*:*:*:*:*:* |
emc | data_protection_advisor | 5.7 | cpe:2.3:a:emc:data_protection_advisor:5.7:*:*:*:*:*:*:* |
emc | data_protection_advisor | 5.7 | cpe:2.3:a:emc:data_protection_advisor:5.7:sp1:*:*:*:*:*:* |
emc | data_protection_advisor | 5.8 | cpe:2.3:a:emc:data_protection_advisor:5.8:*:*:*:*:*:*:* |
emc | data_protection_advisor | 5.8 | cpe:2.3:a:emc:data_protection_advisor:5.8:sp1:*:*:*:*:*:* |