CVE-2017-2768
EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains an Improper Authentication vulnerability that could…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains an Improper Authentication vulnerability that could potentially be exploited by malicious users to compromise the affected system.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.61% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- emc/smarts network configuration manager
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/archive/1/540085/30/0/threadedMailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95936Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037761
- http://www.securityfocus.com/archive/1/540085/30/0/threadedMailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95936Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037761
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.