CVE-2016-0916: Critical severity networker vulnerability
Published Jun 10, 2016
·Updated
EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.
Affected Software
3 affected components
EMC NetWorker>=8.2.1.0<=8.2.1.8
EMC NetWorker>=8.2.2.0<8.2.2.6
EMC NetWorker>=9.0.0.0<9.0.0.6
Event History
Jun 10, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0916?
CVE-2016-0916 is considered a high-severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2016-0916?
To fix CVE-2016-0916, upgrade EMC NetWorker to version 8.2.2.6 or 9.0.0.6 or later.
3
What software is affected by CVE-2016-0916?
CVE-2016-0916 affects EMC NetWorker versions 8.2.1.x, 8.2.2.x prior to 8.2.2.6, and 9.x prior to 9.0.0.6.
4
What type of attack does CVE-2016-0916 exploit?
CVE-2016-0916 exploits improper authentication handling to allow remote attackers to execute arbitrary commands.
5
Is there a workaround for CVE-2016-0916?
There are no definitive workarounds for CVE-2016-0916 besides applying the recommended updates to EMC NetWorker.