CVE-2012-0406: Null Pointer Dereference
The DPAUtilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0406?
CVE-2012-0406 is classified as a medium severity vulnerability due to its potential for denial of service.
How do I fix CVE-2012-0406?
To mitigate CVE-2012-0406, upgrade to a version of EMC Data Protection Advisor that is beyond 5.8 SP1.
What systems are affected by CVE-2012-0406?
CVE-2012-0406 affects EMC Data Protection Advisor versions 5.5 through 5.8 SP1.
What type of attack does CVE-2012-0406 facilitate?
CVE-2012-0406 allows remote attackers to crash the daemon through a NULL pointer dereference.
What command exploits CVE-2012-0406?
The vulnerability can be exploited via an AUTHENTICATECONNECTION command that lacks a password or is empty.