Back
CVE-2017-8020
CRITICAL
An issue was discovered in EMC ScaleIO 2.0.1.x. A buffer overflow vulnerability in the SDBG service may potentially allow a remote unauthenticated attacker to execute arbitrary commands with root privileges on an affected server.
Published: Nov 28, 2017
Modified: Jun 17, 2026
CWE-119
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| emc | scaleio | 2.0.1.0 |
| emc | scaleio | 2.0.1.1 |
| emc | scaleio | 2.0.1.2 |
| emc | scaleio | 2.0.1.3 |
GitHub Security Advisory GHSA-55j8-4mpr-wfvp
An issue was discovered in EMC ScaleIO 2.0.1.x. A buffer overflow vulnerability in the SDBG...
References (4)
- http://seclists.org/fulldisclosure/2017/Nov/35 Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/101995 Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2017/Nov/35 Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/101995 Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
4.21%
Top 10% most likely to be exploited
Threat Score
40.5 / 100
Data Sources
NVD
EPSS
GitHub