CVE-2018-1218
In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer overflow condition when handling certain messages.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer overflow condition when handling certain messages. A remote unauthenticated attacker could potentially exploit this vulnerability to cause a denial of service to the users of NetWorker systems.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 13.44% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- dell/emc networker
- Source
- security_alert@emc.com
References
- http://seclists.org/fulldisclosure/2018/Mar/43Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1040546Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44332/Exploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Mar/43Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1040546Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44332/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.