Back

CVE-2017-14375

CRITICAL

EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.

Published: Nov 1, 2017 Modified: Jun 17, 2026
CWE-290

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
dell emc_unisphere * < 8.4.0.15
emc solutions_enabler * < 8.4.0.15
emc vasa * < 8.4.0.512
emc vmax_emanagement *

GitHub Security Advisory GHSA-3mf6-cpxv-733m

EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler...

References (6)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 4.77%

Top 9% most likely to be exploited

Threat Score 40.6 / 100

Data Sources

NVD EPSS GitHub