CVE-2017-8011
9.8
CRITICAL · CVSS 3.1 · EPSS 14% (pctl 96)
Patch early
EPSS 14% — above the 10% action threshold.
Description
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components. A remote attacker with the knowledge of the default password may potentially use these accounts to run arbitrary web service and remote procedure calls on the affected system.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 14.02% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-07-17 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| dell | emc m\&r |
| dell | emc storage monitoring and reporting |
| dell | emc vipr srm |
| dell | emc vnx monitoring and reporting |
References
→ the Explorer · watch your stack · NVD