Intrusion Prevention



This indicates attack attempt against a Security Bypass vulnerability in EMC Legato Networker.
The vulnerability is due to insufficient access control when handling portmap requests. Remote unauthenticated attackers can exploit the vulnerability by spoofing a source address as "localhost" or "" to register Remote Procedure Call (RPC) services, allowing them to eavesdrop on communications.

Affected Products

EMC Legato NetWorker 7.5 prior to
EMC Legato NetWorker 7.6 prior to


Security Bypass: Remote attackers can bypass the security of vulnerable systems.

Recommended Actions

Refer to the vendor's website for a suggested workaround.

CVE References


Other References

ZDI-11-168 43113