Vulnerabilities > EMC > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-09-21 CVE-2016-0917 Permissions, Privileges, and Access Controls vulnerability in EMC products
The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does not prevent duplicate NTLM challenge-response nonces, which makes it easier for remote attackers to execute arbitrary code, or read or write to files, via a series of authentication requests, a related issue to CVE-2010-0231.
network
low complexity
emc CWE-264
critical
9.8
2016-09-21 CVE-2016-0903 Information Exposure vulnerability in EMC Avamar Server
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client agent.
network
low complexity
emc CWE-200
critical
9.1
2016-09-18 CVE-2016-0922 Improper Authorization vulnerability in EMC Vipr SRM 3.6.0/3.6.4/3.7.1
EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack.
network
low complexity
emc CWE-285
critical
9.8
2016-06-10 CVE-2016-0916 Improper Authentication vulnerability in EMC Networker
EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.
network
low complexity
emc CWE-287
critical
9.8
2008-04-14 CVE-2008-0961 Use of Hard-coded Credentials vulnerability in EMC Diskxtender 6.20.060
EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface.
network
low complexity
emc CWE-798
critical
9.8