CVE-2017-8011: Critical severity dell emc m&r vulnerability
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components. A remote attacker with the knowledge of the default password may potentially use these accounts to run arbitrary web service and remote procedure calls on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8011?
CVE-2017-8011 has a high severity due to the presence of undocumented accounts with default passwords.
How do I fix CVE-2017-8011?
To fix CVE-2017-8011, change the default passwords of the undocumented accounts and implement access controls.
Which EMC products are affected by CVE-2017-8011?
CVE-2017-8011 affects EMC ViPR SRM versions prior to 4.1, EMC Storage M&R versions prior to 4.1, and all versions of EMC VNX M&R.
What are the potential risks of CVE-2017-8011?
The risks of CVE-2017-8011 include unauthorized access to sensitive information and potential manipulation of data.
Is there a known workaround for CVE-2017-8011?
There are no documented workarounds for CVE-2017-8011, so patching the affected software is recommended.