Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Emc

First CVE: Nov 21, 2001Active for: 25 yearsTotal CVEs: 419
33.7
VTI Score
Medium

EMC's vulnerability footprint spans a broadly represented portfolio of enterprise storage, governance, identity management, and content-management platforms that underpin infrastructure and compliance workloads, placing the vendor among the most prominent in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful tendency toward critical severity and a moderate tendency toward public exploit availability; the vendor's identity and governance products, in particular, have been a notable focus of disclosure activity. The exposure recurs across flagship products such as RSA Authentication Manager, RSA Archer EGRC, Documentum Content Server, NetWorker, and Isilon OneFS, and concentrates in weakness classes including cross-site scripting, sensitive-information exposure, and improper input validation—patterns typical of web-facing enterprise applications and administrative interfaces. Defenders should treat this vendor's advisories as broadly relevant to enterprise security posture, particularly for identity and governance systems where misconfigurations or unpatched instances elevate lateral-movement risk; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
419
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Emc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 21, 2001
24 years ago
Most Recent CVE
Jan 12, 2024
924 days ago

Products(186 total)

Top CVEs

Signals from CVEs in this vendor scope (419 CVEs).

419 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-0647HIGH
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary comm
Feb 10, 201110.080NOYES
CVE-2008-2158HIGH
Multiple stack-based buffer overflows in the Command Line Interface process in the Server Agent in EMC AlphaStor 3.1 SP1 for Windows allow remote attackers to execute arbitrary cod
May 29, 200810.076NOYES
CVE-2014-0644HIGH
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjuncti
Apr 17, 20147.867NOYES
CVE-2018-1235CRITICAL
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may
May 29, 20189.866NOYES
CVE-2012-2288HIGH
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via f
Sep 4, 20129.366NOYES
CVE-2013-0928HIGH
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary commands via a DCP "run comm
Jan 21, 20139.365NOYES
CVE-2009-2754HIGH
Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynam
Mar 5, 201010.057NOYES
CVE-2013-0946HIGH
Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary code via crafted commands.
May 10, 20139.356NOYES
CVE-2008-2157HIGH
robotd in the Library Manager in EMC AlphaStor 3.1 SP1 for Windows allows remote attackers to execute arbitrary commands via an unspecified string field in a packet to TCP port 350
May 29, 200810.054NOYES
CVE-2012-2515HIGH
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Docum
Jul 5, 20129.353NOYES
View all 419 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products419 CVEs
47%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local30 (7.2%)
Network113 (27.0%)
Unknown273 (65.2%)
Physical2 (0.5%)
Adjacent Network1 (0.2%)
Attack Complexity
Low135 (32.2%)
High11 (2.6%)
Unknown273 (65.2%)
User Interaction
None105 (25.1%)
Unknown273 (65.2%)
Required41 (9.8%)
Privileges Required
Low56 (13.4%)
High22 (5.3%)
None68 (16.2%)
Unknown273 (65.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (419 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
7 CVEs
1.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
24 CVEs
5.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Emc.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Emc — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Emc's Products

View all 9 CNAs →

Top CWEs