EMC's vulnerability footprint spans a broadly represented portfolio of enterprise storage, governance, identity management, and content-management platforms that underpin infrastructure and compliance workloads, placing the vendor among the most prominent in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful tendency toward critical severity and a moderate tendency toward public exploit availability; the vendor's identity and governance products, in particular, have been a notable focus of disclosure activity. The exposure recurs across flagship products such as RSA Authentication Manager, RSA Archer EGRC, Documentum Content Server, NetWorker, and Isilon OneFS, and concentrates in weakness classes including cross-site scripting, sensitive-information exposure, and improper input validation—patterns typical of web-facing enterprise applications and administrative interfaces. Defenders should treat this vendor's advisories as broadly relevant to enterprise security posture, particularly for identity and governance systems where misconfigurations or unpatched instances elevate lateral-movement risk; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Emc over time
Signals from CVEs in this vendor scope (419 CVEs).
419 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-0647HIGH The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary comm | Feb 10, 2011 | 10.0 | 80 | NO | YES |
CVE-2008-2158HIGH Multiple stack-based buffer overflows in the Command Line Interface process in the Server Agent in EMC AlphaStor 3.1 SP1 for Windows allow remote attackers to execute arbitrary cod | May 29, 2008 | 10.0 | 76 | NO | YES |
CVE-2014-0644HIGH EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjuncti | Apr 17, 2014 | 7.8 | 67 | NO | YES |
CVE-2018-1235CRITICAL Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may | May 29, 2018 | 9.8 | 66 | NO | YES |
CVE-2012-2288HIGH Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via f | Sep 4, 2012 | 9.3 | 66 | NO | YES |
CVE-2013-0928HIGH The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary commands via a DCP "run comm | Jan 21, 2013 | 9.3 | 65 | NO | YES |
CVE-2009-2754HIGH Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynam | Mar 5, 2010 | 10.0 | 57 | NO | YES |
CVE-2013-0946HIGH Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary code via crafted commands. | May 10, 2013 | 9.3 | 56 | NO | YES |
CVE-2008-2157HIGH robotd in the Library Manager in EMC AlphaStor 3.1 SP1 for Windows allows remote attackers to execute arbitrary commands via an unspecified string field in a packet to TCP port 350 | May 29, 2008 | 10.0 | 54 | NO | YES |
CVE-2012-2515HIGH Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Docum | Jul 5, 2012 | 9.3 | 53 | NO | YES |
Signals from CVEs in this vendor scope (419 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Emc.
Media articles that mention a CVE ID that affects a product developed by Emc — matched by CVE ID, not by vendor name.