Lucene search

K
nvd[email protected]NVD:CVE-2017-4987
HistoryJun 19, 2017 - 12:29 p.m.

CVE-2017-4987

2017-06-1912:29:00
CWE-427
web.nvd.nist.gov
2

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

18.9%

In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user can load a maliciously crafted file in the search path which may potentially allow the attacker to execute arbitrary code on the targeted VNX Control Station system, aka an uncontrolled search path vulnerability.

Affected configurations

Nvd
Node
emcvnx2_firmwareMatch-
AND
emcvnx2Match-
Node
emcvnx1_firmwareMatch-
AND
emcvnx1Match-
VendorProductVersionCPE
emcvnx2_firmware-cpe:2.3:o:emc:vnx2_firmware:-:*:*:*:*:*:*:*
emcvnx2-cpe:2.3:h:emc:vnx2:-:*:*:*:*:*:*:*
emcvnx1_firmware-cpe:2.3:o:emc:vnx1_firmware:-:*:*:*:*:*:*:*
emcvnx1-cpe:2.3:h:emc:vnx1:-:*:*:*:*:*:*:*

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

18.9%

Related for NVD:CVE-2017-4987