Vulnerability record · CVE-2011-0647 · published 10 February 2011
CVE-2011-0647: EMC Replication Manager and NetWorker irccd.exe remote command execution
Emc · Replication Manager
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x fails to validate input passed to the RunProgram function on TCP port 6542. A remote, unauthenticated attacker can send crafted requests to that port and execute arbitrary commands on the host. The flaw is rated 10.0 under CVSS 2.0, reflecting full loss of confidentiality, integrity and availability.
Description
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution with a CVSS 2.0 score of 10.0 and very high EPSS percentile warrants immediate remediation despite no KEV listing.
What it is
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x fails to validate input passed to the RunProgram function on TCP port 6542. A remote, unauthenticated attacker can send crafted requests to that port and execute arbitrary commands on the host. The flaw is rated 10.0 under CVSS 2.0, reflecting full loss of confidentiality, integrity and availability.
Impact
An attacker gains remote code execution with the privileges of the irccd.exe service, allowing full control of the affected host and any data or backup operations it manages.
Attack surface
Reachable over the network via TCP port 6542; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is 0.63676 (99.18th percentile), indicating a high modeled likelihood of exploitation; references include vendor advisories and a Zero Day Initiative advisory but no public exploit tag.
What to do
- Upgrade EMC Replication Manager Client to 5.3 or later and NetWorker Module for Microsoft Applications to a fixed release.
- Block or restrict inbound TCP port 6542 to trusted management hosts only.
- Isolate backup and replication management networks from general user and internet-facing segments.
- Monitor EMC advisories for updated fixed versions if the listed releases are no longer supported.
Detection
- Monitor network traffic to TCP port 6542 for unexpected or external source addresses.
- Alert on irccd.exe spawning child processes such as cmd.exe or other shells.
- Review host logs for anomalous process creation under the irccd.exe service account.
- Baseline normal irccd.exe connections and flag deviations in source IP or frequency.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0647 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0647), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.