CVE-2012-0406
20.04.2012, 04:02
The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.Enginsight
Vendor | Product | Version |
---|---|---|
emc | data_protection_advisor | 5.5 |
emc | data_protection_advisor | 5.5:sp1 |
emc | data_protection_advisor | 5.6 |
emc | data_protection_advisor | 5.6:sp1 |
emc | data_protection_advisor | 5.7 |
emc | data_protection_advisor | 5.7:sp1 |
emc | data_protection_advisor | 5.8 |
emc | data_protection_advisor | 5.8:sp1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References