Back

CVE-2017-2767

CRITICAL

EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains a Java RMI Remote Code Execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.

Published: Feb 3, 2017 Modified: Jun 17, 2026
CWE-287

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
emc smarts_network_configuration_manager 9.3
emc smarts_network_configuration_manager 9.4
emc smarts_network_configuration_manager 9.4.1
emc smarts_network_configuration_manager 9.4.2

GitHub Security Advisory GHSA-xqv8-w96f-56rp

EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x,...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.76%

Top 8% most likely to be exploited

Threat Score 40.9 / 100

Data Sources

NVD EPSS GitHub