CVE-2017-8011: Dell Emc M&r

Critical severity, CVSS 9.8. EPSS: 14% chance of exploitation in the next 30 days.

EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components. A remote attacker with the knowledge of the default password may potentially use these accounts to run arbitrary web service and remote procedure calls on the affected system.

Affected products

  • Dell Emc M&r: affected versions not specified
  • Dell Emc Storage Monitoring And Reporting: version 4.0.2 only
  • Dell Emc Vipr Srm: up to and including 4.0.2
  • Dell Emc Vnx Monitoring And Reporting: affected versions not specified

Published 2017-07-17. Last modified 2026-06-17.