← Vulnerability feed

Vulnerability record · CVE-2016-0916 · published 10 June 2016

CVE-2016-0916: Emc networker improper authentication vulnerability

Emc · Networker

EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.

9.8 CVSS 3.0 Critical EPSS 7.7% · top 5.6% CWE-287 · Improper authentication
9.8CVSS 3.0 base score, v2 10.0
7.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/bugtraq/2016/Jun/43 Third Party Advisory
http://www.securitytracker.com/id/1036075 Third Party AdvisoryVDB Entry
http://seclists.org/bugtraq/2016/Jun/43 Third Party Advisory
http://www.securitytracker.com/id/1036075 Third Party AdvisoryVDB Entry

Track CVE-2016-0916 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-3892Emc networker vulnerabilityThe Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote …EPSS 4.5%9.8CVE-2017-15548Emc avamar server improper authentication vulnerabilityAn issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Inte…EPSS 4.7%9.3CVE-2012-4607Emc networker memory buffer overflow vulnerabilityBuffer overflow in nsrindexd in EMC NetWorker 7.5.x and 7.6.x before 7.6.5, and 8.x before 8.0.0.6, allows remote attackers to execute arbitrary code…EPSS 3.2%9.3CVE-2012-2288Emc networker vulnerabilityFormat string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers …EPSS 33%9.3CVE-2012-0395Emc networker memory buffer overflow vulnerabilityBuffer overflow in the server in EMC NetWorker 7.5.x and 7.6.x before 7.6.3 SP1 Cumulative Release build 851 allows remote attackers to cause a denia…EPSS 3.0%8.8CVE-2017-15549Emc avamar server unrestricted file upload vulnerabilityAn issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Inte…EPSS 5.5%8.8CVE-2017-15550Emc avamar server path traversal vulnerabilityAn issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Inte…EPSS 8.2%8.1CVE-2017-8022Emc networker memory buffer overflow vulnerabilityAn issue was discovered in EMC NetWorker (prior to 8.2.4.9, all supported 9.0.x versions, prior to 9.1.1.3, prior to 9.2.0.4). The Server service (ns…EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2016-0916), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.