PT-2017-18066 · Dell Emc+1 · Dell Emc Vnx Monitoring/Reporting+1
Published
2017-09-22
·
Updated
2021-09-13
·
CVE-2017-8012
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell EMC VNX Monitoring and Reporting versions (affected versions not specified)
Description
The issue concerns the Java Management Extensions (JMX) protocol used for communication between components in the Alerting and/or Compliance components. This can be exploited to create a denial of service (DoS) condition. Attackers with knowledge of JMX agent user credentials could potentially create arbitrary files on the affected system, leveraging inherent JMX protocol capabilities to create a DoS condition.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Emc Vnx Monitoring/Reporting
Java Management Extensions