The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2012-04-20 04:02
Updated : 2012-08-14 03:33
NVD link : CVE-2012-0406
Mitre link : CVE-2012-0406
CVE.ORG link : CVE-2012-0406
JSON object : View
Products Affected
emc
- data_protection_advisor
CWE
CWE-264
Permissions, Privileges, and Access Controls