CVE-2017-14375
Last modified
CVE-2017-14375 is a vulnerability of currently unknown severity. EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.. EPSS estimates a 4.77% chance of exploitation in the next 30 days.
Description
EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Emc Unisphere | < 8.4.0.15 |
| Emc | Solutions Enabler | < 8.4.0.15 |
| Emc | Vasa | < 8.4.0.512 |
| Emc | Vmax Emanagement | <= 1.4 |
References
- http://seclists.org/fulldisclosure/2017/Oct/70Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/101673Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039704Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2017/Oct/70Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/101673Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039704Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14375?
How severe is CVE-2017-14375?
How do I fix CVE-2017-14375?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14369RSA Archer GRC Platform prior to 6.2.0.5 is affected by a pr…
- CVE-2017-14370RSA Archer GRC Platform prior to 6.2.0.5 is affected by stor…
- CVE-2017-14371RSA Archer GRC Platform prior to 6.2.0.5 is affected by refl…
- CVE-2017-14372RSA Archer GRC Platform prior to 6.2.0.5 is affected by refl…
- CVE-2017-14373EMC RSA Authentication Manager 8.2 SP1 P4 and earlier contai…
- CVE-2017-14374The SMI-S service in Dell Storage Manager versions earlier t…
- CVE-2017-14376EMC AppSync Server prior to 3.5.0.1 contains database accoun…
- CVE-2017-14377EMC RSA Authentication Agent for Web: Apache Web Server vers…
- CVE-2017-14378EMC RSA Authentication Agent API 8.5 for C and RSA Authentic…
- CVE-2017-14379EMC RSA Authentication Manager before 8.2 SP1 P6 has a cross…
- CVE-2017-1438IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.…
- CVE-2017-14380In EMC Isilon OneFS 8.1.0.0, 8.0.1.0 - 8.0.1.1, 8.0.0.0 - 8.…
Are you affected by CVE-2017-14375?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
