{"api_version":"1","generated_at":"2026-07-23T04:05:26+00:00","cve":"CVE-2012-2288","urls":{"html":"https://cve.report/CVE-2012-2288","api":"https://cve.report/api/cve/CVE-2012-2288.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-2288","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-2288"},"summary":{"title":"CVE-2012-2288","description":"Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via format string specifiers in a message.","state":"PUBLISHED","assigner":"dell","published_at":"2012-09-04 11:04:48","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-134","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://archives.neohapsis.com/archives/bugtraq/2012-08/0219.html","name":"http://archives.neohapsis.com/archives/bugtraq/2012-08/0219.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securitytracker.com/id?1027459","name":"http://www.securitytracker.com/id?1027459","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC NetWorker NSRD RPC Format String Flaw Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/55330","name":"http://www.securityfocus.com/bid/55330","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EMC NetWorker 'nsrd' RPC Service Format String Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-2288","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2288","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"2288","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"networker","cpe6":"7.6.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"2288","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"networker","cpe6":"7.6.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"2288","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"networker","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T19:26:09.006Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"55330","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/55330"},{"name":"20120830 ESA-2012-038: EMC NetWorker Format String Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2012-08/0219.html"},{"name":"1027459","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1027459"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-08-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via format string specifiers in a message."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2013-02-14T10:00:00.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"55330","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/55330"},{"name":"20120830 ESA-2012-038: EMC NetWorker Format String Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2012-08/0219.html"},{"name":"1027459","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1027459"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2012-2288","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via format string specifiers in a message."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"55330","refsource":"BID","url":"http://www.securityfocus.com/bid/55330"},{"name":"20120830 ESA-2012-038: EMC NetWorker Format String Vulnerability","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2012-08/0219.html"},{"name":"1027459","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1027459"}]}}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2012-2288","datePublished":"2012-09-04T10:00:00.000Z","dateReserved":"2012-04-19T00:00:00.000Z","dateUpdated":"2024-08-06T19:26:09.006Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-09-04 11:04:48","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-134","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:emc:networker:7.6.3:*:*:*:*:*:*:*","matchCriteriaId":"ADBD90BD-A1F7-45D6-9BD3-19AF88FD6087"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:networker:7.6.4:*:*:*:*:*:*:*","matchCriteriaId":"BEF6BADD-1761-4F58-8FE6-34824D36A42A"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:networker:8.0:*:*:*:*:*:*:*","matchCriteriaId":"83625C74-9A2C-406D-A72F-98057C626180"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"2288","Ordinal":"1","Title":"CVE-2012-2288","CVE":"CVE-2012-2288","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"2288","Ordinal":"1","NoteData":"Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via format string specifiers in a message.","Type":"Description","Title":"CVE-2012-2288"},{"CveYear":"2012","CveId":"2288","Ordinal":"2","NoteData":"2012-09-04","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"2288","Ordinal":"3","NoteData":"2013-02-14","Type":"Other","Title":"Modified"}]}}}