peter bassill · operator
$ cve CVE-2017-14375 JSON

CVE-2017-14375

9.8
CRITICAL · CVSS 3.0 · EPSS 4.8% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.77% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-290
On CISA KEVno
Public exploitnone known
Published2017-11-01
Last modified2026-06-17

Affected (4)

VendorProduct
dellemc unisphere
emcsolutions enabler
emcvasa
emcvmax emanagement

References

→ the Explorer  ·  watch your stack  ·  NVD