First published: Sun Sep 18 2016(Updated: )
EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC ViPR SRM | <=3.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0922 is classified as a medium severity vulnerability due to its potential for remote exploitation through brute-force attacks.
To remediate CVE-2016-0922, upgrade EMC ViPR SRM to version 3.7.2 or later.
Failure to address CVE-2016-0922 may allow attackers to compromise the system through repeated password attempts.
EMC ViPR SRM versions prior to 3.7.2, specifically up to 3.7.1, are affected by CVE-2016-0922.
Yes, CVE-2016-0922 can be exploited remotely, allowing attackers to perform unauthorized access attempts.