peter bassill · operator
$ cve CVE-2017-8011 JSON

CVE-2017-8011

9.8
CRITICAL · CVSS 3.1 · EPSS 14% (pctl 96)

Patch early

EPSS 14% — above the 10% action threshold.

Description

EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components. A remote attacker with the knowledge of the default password may potentially use these accounts to run arbitrary web service and remote procedure calls on the affected system.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS14.02% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2017-07-17
Last modified2026-06-17

Affected (4)

VendorProduct
dellemc m\&r
dellemc storage monitoring and reporting
dellemc vipr srm
dellemc vnx monitoring and reporting

References

→ the Explorer  ·  watch your stack  ·  NVD