A high severity vulnerability found in the curl library (libcurl) used by Embedded Entitlement
Manager(EEM) bundled with Harvest V14.5 release.
Release: v14.5
This vulnerability applies to Harvest only when it uses certificate based authentication with
Embedded Entitlement Manager (EEM) and specific to V14.5 release only.
EEM product advisory is available here:
https://knowledge.broadcom.com/external/article/274800
Based on further investigation ,it is now concluded that EEM is not using SOCKS5 proxy for connecting to remote hosts. While the version used is vulnerable, they are not exploitable since SOCKS5 proxy is not enabled.
Harvest v14.5 when used with EEM is not impacted with this vulnerability and hence no further action required.