PT-2011-2525 · Emc+1 · Networker Module For Microsoft Applications+2
Published
2011-02-07
·
Updated
2018-10-09
·
CVE-2011-0647
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
EMC Replication Manager Client versions prior to 5.3
NetWorker Module for Microsoft Applications versions 2.1.x through 2.2.x
Description
The issue allows remote attackers to execute arbitrary commands. This is achieved via the
RunProgram function to TCP port 6542.Recommendations
For EMC Replication Manager Client versions prior to 5.3, update to version 5.3 or later.
For NetWorker Module for Microsoft Applications versions 2.1.x through 2.2.x, consider disabling the
RunProgram function as a temporary workaround until a patch is available. Restrict access to TCP port 6542 to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emc Replication Manager Client
Applications
Networker Module For Microsoft Applications