Emc Networker

Vendor:

First CVE: Mar 19, 2018 · Active for 8 years

18
Total CVEs
More Total CVEs than 93% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Emc Networker over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 19, 2018
8 years ago
Most Recent CVE
Dec 18, 2023
952 days ago

CVE Severity & Scoring

Emc Networker18 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local3 (16.7%)
Network13 (72.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (11.1%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None17 (94.4%)
Unknown0 (0.0%)
Required1 (5.6%)
Privileges Required
Low9 (50.0%)
High3 (16.7%)
None6 (33.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer overflow condition when handlin
Mar 19, 20187.542NOYES
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrexecd) when oldauth authenticati
Apr 1, 20199.833NONO
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution service (nsrexecd) irrespective of any au
Feb 3, 20239.830NONO
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanc
Aug 1, 20188.827NONO
Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privileges may exploit this vulnerability to
Nov 23, 20217.825NONO
Dell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Permissions or Privileges vulnerability. Authenticated non admi
Aug 30, 20226.522NONO
Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with low privileges may exploit this vulnerability to perform 'n
Oct 16, 20206.522NONO
Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to
Oct 16, 20206.522NONO
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially
Mar 1, 20236.521NONO
Dell EMC NetWorker, 19.4 or older, contain an uncontrolled resource consumption flaw in its API service. An authorized API user could potentially exploit this vulnerability via the
Aug 10, 20216.521NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Emc Networker

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
19.7.0.219.81.0%00
19.7.0.016.50.3%00
19.6.114.60.3%00
19.4.0.015.50.2%00
18.2.0.015.50.2%00
18.1.0.215.50.2%00
18.1.0.127.20.5%00