CVE-2017-10955 - CVE House
Back to Database
Status published Unknown CVE-2017-10955

This vulnerability allows remote attackers to execute arbitrary code on...

Vulnerability Description

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication is required to exploit this vulnerability. The specific flaw exists within the EMC DPA Application service, which listens on TCP port 9002 by default. When parsing the preScript parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute arbitrary code under the context of SYSTEM. Was ZDI-CAN-4697. NOTE: Dell EMC disputes that this is a vulnerability

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-10955

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Dell EMC Data Protection Advisor
Vulnerable Versions:
6.3.0

Timeline

Official Publish: October 19th, 2017
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)