Back

CVE-2017-4997

CRITICAL

EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.

Published: Jun 29, 2017 Modified: Jun 17, 2026
CWE-20

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
dell emc_vasa_provider_virtual_appliance *

GitHub Security Advisory GHSA-5279-r4h4-5379

EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code...

References (4)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 4.48%

Top 9% most likely to be exploited

Threat Score 40.5 / 100

Data Sources

NVD EPSS GitHub