Remote Code Execution Flaw in EMC Data Protection Advisor by Dell EMC
CVE-2017-10955
What is CVE-2017-10955?
This vulnerability permits remote attackers to execute arbitrary code on installations of EMC Data Protection Advisor version 6.3.0. Authenticating users are at risk due to a flaw in the EMC DPA Application service, which listens on TCP port 9002 by default. The flaw arises from improper validation of the preScript parameter, allowing an attacker to exploit it to execute system calls. As a result, the attacker can gain arbitrary code execution with SYSTEM privileges. Dell EMC has stated its position that this does not constitute a vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Dell EMC Data Protection Advisor 6.3.0
References
EPSS Score
33% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved