peter bassill · operator
$ cve CVE-2017-4984 JSON

CVE-2017-4984

9.8
CRITICAL · CVSS 3.0 · EPSS 6.6% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able to elevate their permissions to root through a command injection. This may potentially be exploited by an attacker to run arbitrary code with root-level privileges on the targeted VNX Control Station system, aka remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.57% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2017-06-19
Last modified2026-06-17

Affected (4)

VendorProduct
emcvnx1
emcvnx1 firmware
emcvnx2
emcvnx2 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD