VulnerabilityModified
CVE-2011-1421
EMC NetWorker 7.5.x before 7.5.4.3 and 7.6.x before 7.6.1.5, when the client push feature is enabled, uses weak permissions for an unspecified file, which allows local users to gain privileges via unknown vectors.
MEDIUM 6.9EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
EMC NetWorker 7.5.x before 7.5.4.3 and 7.6.x before 7.6.1.5, when the client push feature is enabled, uses weak permissions for an unspecified file, which allows local users to gain privileges via unknown vectors.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.31% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- emc/networker
- Source
- security_alert@emc.com
References
- http://secunia.com/advisories/44237Vendor Advisory
- http://securityreason.com/securityalert/8214
- http://securitytracker.com/id?1025383
- http://www.securityfocus.com/archive/1/517532/100/0/threaded
- http://www.securityfocus.com/bid/47410
- http://www.vupen.com/english/advisories/2011/1025Vendor Advisory
- http://secunia.com/advisories/44237Vendor Advisory
- http://securityreason.com/securityalert/8214
- http://securitytracker.com/id?1025383
- http://www.securityfocus.com/archive/1/517532/100/0/threaded
- http://www.securityfocus.com/bid/47410
- http://www.vupen.com/english/advisories/2011/1025Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.