← Vulnerability feed

Vulnerability record · CVE-2017-14375 · published 1 November 2017

CVE-2017-14375: Dell emc unisphere authentication bypass by spoofing vulnerability

Dell · Emc Unisphere

EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.

9.8 CVSS 3.0 Critical EPSS 4.8% · top 8.4% CWE-290 · Authentication bypass by spoofing
9.8CVSS 3.0 base score, v2 10.0
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2017/Oct/70 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/101673 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039704 Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2017/Oct/70 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/101673 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039704 Third Party AdvisoryVDB Entry

Track CVE-2017-14375 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-1183Dell emc smis xml external entity (xxe) vulnerabilityIn Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, D…EPSS 2.0%9.8CVE-2016-6646Dell emc unisphere improper input validation vulnerabilityThe vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3…EPSS 4.9%9.8CVE-2016-0889Dell emc unisphere improper input validation vulnerabilityAn HTTP servlet in vApp Manager in EMC Unisphere for VMAX Virtual Appliance before 8.2.0 allows remote attackers to write to arbitrary files via a cr…EPSS 3.1%8.8CVE-2016-6645Dell emc unisphere improper input validation vulnerabilityThe vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3…EPSS 3.6%1.9CVE-2013-3287Dell emc unisphere vulnerabilityEMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cl…EPSS 0.30%6.5CVE-2023-50224TP-Link router httpd authentication bypass exposes stored credentialsThe httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass…KEVEPSS 16%analysed10.0CVE-2024-54085AMI MegaRAC SPx BMC authentication bypass via Redfish Host InterfaceAMI's SPx BMC implementation contains an authentication bypass reachable remotely through the Redfish Host Interface, classified as CWE-290 (authenti…KEVEPSS 61%analysed9.8CVE-2024-4358Progress Telerik Report Server authentication bypass via spoofingTelerik Report Server 2024 Q1 (10.0.24.305) and earlier on IIS contains an authentication bypass by spoofing (CWE-290). An unauthenticated remote att…KEVEPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2017-14375), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.