CVE-2011-0647
UnknownEPSS 63.68%
Last modified
CVE-2011-0647 is a vulnerability of currently unknown severity. The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.. EPSS estimates a 63.68% chance of exploitation in the next 30 days.
Description
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emc | Replication Manager | <= 5.2.3 |
| Emc | Replication Manager | 2.0 |
| Emc | Replication Manager | 5.2 |
| Emc | Replication Manager | 5.2.2 |
| Emc | Networker Module | 2.1 |
| Emc | Networker Module | 2.2 |
References
- http://secunia.com/advisories/43164Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0304Vendor Advisory
- http://secunia.com/advisories/43164Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0304Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0647?
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
How severe is CVE-2011-0647?
Severity scoring for CVE-2011-0647 is pending analysis. The EPSS model estimates a 63.68% probability of exploitation in the next 30 days.
How do I fix CVE-2011-0647?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-0641Multiple cross-site scripting (XSS) vulnerabilities in wp-ad…
- CVE-2011-0642Cross-site request forgery (CSRF) vulnerability in news/admi…
- CVE-2011-0643Cross-site request forgery (CSRF) vulnerability in admin/con…
- CVE-2011-0644SQL injection vulnerability in include/admin/model_field.cla…
- CVE-2011-0645SQL injection vulnerability in data.php in PHPCMS 2008 V2 al…
- CVE-2011-0646SQL injection vulnerability in viewfaqs.php in PHP LOW BIDS …
- CVE-2011-0648Unspecified vulnerability in EMC Avamar before 5.0.4-30 allo…
- CVE-2011-0649Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2…
- CVE-2011-0650Cross-site request forgery (CSRF) vulnerability in Greenbone…
- CVE-2011-0651Buffer overflow in the key exchange functionality in Icon La…
- CVE-2011-0652lnsfw1.sys 6.0.2900.5512 in Look 'n' Stop Firewall 2.06p4 an…
- CVE-2011-0653Cross-site scripting (XSS) vulnerability in Microsoft Office…
Are you affected by CVE-2011-0647?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
