← Vulnerability feed

Vulnerability record · CVE-2017-14384 · published 16 March 2018

CVE-2017-14384: Dell storage manager path traversal vulnerability

Dell · Storage Manager

In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote malicious user could potentially exploit this vulnerability to read unauthorized files by supplying specially crafted strings in input parameters of the application. A malicious user cannot delete or modify any files via this vulnerability.

6.5 CVSS 3.0 Medium EPSS 1.8% · top 22.3% CWE-22 · Path traversal
6.5CVSS 3.0 base score, v2 4.0
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote malicious user could potentially exploit this vulnerability to read unauthorized files by supplying specially crafted strings in input parameters of the application. A malicious user cannot delete or modify any files via this vulnerability.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-14384 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-43995Dell storage manager improper authentication vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with…EPSS 0.84%9.8CVE-2017-14374Dell storage manager hard-coded credentials vulnerabilityThe SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with…EPSS 1.3%8.8CVE-2025-22477Dell storage manager improper authentication vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with…EPSS 0.29%8.1CVE-2025-22478Dell storage manager xml external entity (xxe) vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An…EPSS 0.27%8.0CVE-2025-22476Dell storage manager command injection vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command…EPSS 0.55%7.5CVE-2025-43994Dell storage manager missing authentication for critical function vulnerabilityDell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unaut…EPSS 0.60%6.5CVE-2025-46425Dell storage manager xml external entity (xxe) vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A …EPSS 0.33%5.2CVE-2025-23379Dell storage manager cross-site scripting vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-sit…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2017-14384), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.