SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-8007

In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability.

HIGH 8.8EPSS 2.96%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
2.96% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
dell/emc m\&r · dell/emc storage monitoring and reporting · dell/emc vipr srm · dell/emc vnx monitoring and reporting
Source
security_alert@emc.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.