PT-2017-18066 · Dell Emc+1 · Dell Emc Vnx Monitoring/Reporting+1

Published

2017-09-22

·

Updated

2021-09-13

·

CVE-2017-8012

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC VNX Monitoring and Reporting versions (affected versions not specified)
Description The issue concerns the Java Management Extensions (JMX) protocol used for communication between components in the Alerting and/or Compliance components. This can be exploited to create a denial of service (DoS) condition. Attackers with knowledge of JMX agent user credentials could potentially create arbitrary files on the affected system, leveraging inherent JMX protocol capabilities to create a DoS condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-8012
ZDI-17-826

Affected Products

Dell Emc Vnx Monitoring/Reporting
Java Management Extensions