PT-2020-7058 · Emc · Emc Replistor Server Service
Published
2020-01-15
·
Updated
2020-01-24
·
CVE-2009-1120
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
EMC RepliStor Server Service versions before ESA-09-003
Description
The issue is caused by an error when the rep srv.exe process handles a specially crafted packet sent by an unauthenticated attacker. This flaw exists within the DoRcvRpcCall RPC function.
Recommendations
For versions before ESA-09-003, update to a version that includes the ESA-09-003 patch to resolve the issue. As a temporary workaround, consider restricting access to the rep srv.exe process to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Emc Replistor Server Service