CVE-2017-14384
Last modified
CVE-2017-14384 is a vulnerability of currently unknown severity. In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote malicious user could potentially exploit this vulnerability to read unauthorized files by supplying specially crafted strings in input parameters of the application. EPSS estimates a 1.91% chance of exploitation in the next 30 days.
Description
In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote malicious user could potentially exploit this vulnerability to read unauthorized files by supplying specially crafted strings in input parameters of the application. A malicious user cannot delete or modify any files via this vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Storage Manager | < 16.3.20 |
References
- http://www.securityfocus.com/bid/103467Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/103467Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14384?
How severe is CVE-2017-14384?
How do I fix CVE-2017-14384?
Are you affected by CVE-2017-14384?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
