Lucene search

K
cveDellCVE-2017-4987
HistoryJun 19, 2017 - 12:29 p.m.

CVE-2017-4987

2017-06-1912:29:00
CWE-427
dell
web.nvd.nist.gov
24
emc
vnx2
vnx1
oe
uncontrolled search path
vulnerability
cve-2017-4987
nvd

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

18.9%

In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user can load a maliciously crafted file in the search path which may potentially allow the attacker to execute arbitrary code on the targeted VNX Control Station system, aka an uncontrolled search path vulnerability.

Affected configurations

Nvd
Node
emcvnx2_firmwareMatch-
AND
emcvnx2Match-
Node
emcvnx1_firmwareMatch-
AND
emcvnx1Match-
VendorProductVersionCPE
emcvnx2_firmware-cpe:2.3:o:emc:vnx2_firmware:-:*:*:*:*:*:*:*
emcvnx2-cpe:2.3:h:emc:vnx2:-:*:*:*:*:*:*:*
emcvnx1_firmware-cpe:2.3:o:emc:vnx1_firmware:-:*:*:*:*:*:*:*
emcvnx1-cpe:2.3:h:emc:vnx1:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "EMC VNX2 versions prior to OE for File 8.1.9.211, EMC VNX1 versions prior to OE for File 7.1.80.8",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "EMC VNX2 versions prior to OE for File 8.1.9.211, EMC VNX1 versions prior to OE for File 7.1.80.8"
      }
    ]
  }
]

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

18.9%

Related for CVE-2017-4987