{
    "id": "CVE-2012-2288",
    "published": "2012-09-04 11:04:48",
    "last_modified": "2026-06-16 23:41:17",
    "cvss_score": "9.3",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
    "cwe": "CWE-134",
    "description": "Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via format string specifiers in a message.",
    "epss_score": "0.33120",
    "epss_percentile": "0.98313",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-27 18:17:11",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "emc",
            "product": "networker"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "22525",
            "title": "EMC NetWorker - Format String (Metasploit)",
            "date": "2012-11-07",
            "url": "https://www.exploit-db.com/exploits/22525"
        }
    ],
    "refs_list": [
        "http://archives.neohapsis.com/archives/bugtraq/2012-08/0219.html",
        "http://www.securityfocus.com/bid/55330",
        "http://www.securitytracker.com/id?1027459",
        "http://archives.neohapsis.com/archives/bugtraq/2012-08/0219.html",
        "http://www.securityfocus.com/bid/55330",
        "http://www.securitytracker.com/id?1027459"
    ]
}