CVE-2016-0922: Critical severity dell emc vipr srm vulnerability
Published Sep 18, 2016
·Updated
EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack.
Affected Software
1 affected component
EMC ViPR SRM<=3.7.1
Event History
Sep 18, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0922?
CVE-2016-0922 is classified as a medium severity vulnerability due to its potential for remote exploitation through brute-force attacks.
2
How do I fix CVE-2016-0922?
To remediate CVE-2016-0922, upgrade EMC ViPR SRM to version 3.7.2 or later.
3
What are the consequences of not addressing CVE-2016-0922?
Failure to address CVE-2016-0922 may allow attackers to compromise the system through repeated password attempts.
4
Which versions of EMC ViPR SRM are affected by CVE-2016-0922?
EMC ViPR SRM versions prior to 3.7.2, specifically up to 3.7.1, are affected by CVE-2016-0922.
5
Can CVE-2016-0922 be exploited remotely?
Yes, CVE-2016-0922 can be exploited remotely, allowing attackers to perform unauthorized access attempts.