peter bassill · operator
$ cve CVE-2017-8023 JSON

CVE-2017-8023

9.8
CRITICAL · CVSS 3.0 · EPSS 5.9% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrexecd) when oldauth authentication method is used. An unauthenticated remote attacker could send arbitrary commands via RPC service to be executed on the host system with the privileges of the nsrexecd service, which runs with administrative privileges.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.88% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2019-04-01
Last modified2026-06-17

Affected (1)

VendorProduct
dellemc networker

References

→ the Explorer  ·  watch your stack  ·  NVD