SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-8003

EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability.

MEDIUM 4.9EPSS 2.58%

Does this matter?

Lower severity and a low EPSS score (2.58%). Track it; it rarely justifies an emergency change on its own.

Description

EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. A remote authenticated high privileged user may potentially exploit this vulnerability to access unauthorized information from the underlying OS server by supplying specially crafted strings in input parameters of the application.

CVSS 3.0
4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
2.58% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
emc/data protection advisor
Source
security_alert@emc.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.