Vulnerability record · CVE-2017-4987 · published 19 June 2017
CVE-2017-4987: Emc vnx2 firmware uncontrolled search path element vulnerability
Emc · Vnx2 Firmware
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user can load a maliciously crafted file in the search path which may potentially allow the attacker to execute arbitrary code on the targeted VNX Control Station system, aka an uncontrolled search path vulnerability.
Description
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user can load a maliciously crafted file in the search path which may potentially allow the attacker to execute arbitrary code on the targeted VNX Control Station system, aka an uncontrolled search path vulnerability.
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/archive/1/540738/30/0/threaded | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/99045 | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/archive/1/540738/30/0/threaded | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/99045 | Third Party AdvisoryVDB Entry |
Track CVE-2017-4987 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-4987), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.