Lucene search

K
cveDellCVE-2012-2282
HistoryJul 16, 2012 - 8:55 p.m.

CVE-2012-2282

2012-07-1620:55:00
CWE-264
dell
web.nvd.nist.gov
23
emc
celerra
network server
vnx
vnxe
nfs
security vulnerability
access control
cve-2012-2282

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

56.3%

EMC Celerra Network Server 6.x before 6.0.61.0, VNX 7.x before 7.0.53.2, and VNXe 2.0 and 2.1 before 2.1.3.19077 (aka MR1 SP3.2) and 2.2 before 2.2.0.19078 (aka MR2 SP0.2) do not properly implement NFS access control, which allows remote authenticated users to read or modify files via a (1) NFSv2, (2) NFSv3, or (3) NFSv4 request.

Affected configurations

Nvd
Node
emccelerra_network_serverMatch6.0.36.4
OR
emccelerra_network_serverMatch6.0.60.2
Node
emcvnxMatch7.0.12.0
OR
emcvnxMatch7.0.53.1
Node
emcvnxeMatch2.0
OR
emcvnxeMatch2.0sp1
OR
emcvnxeMatch2.0sp2
OR
emcvnxeMatch2.0sp3
OR
emcvnxeMatchmr1sp1
OR
emcvnxeMatchmr1sp2
OR
emcvnxeMatchmr1sp3
OR
emcvnxeMatchmr1sp3.1
OR
emcvnxeMatchmr2sp0.1
VendorProductVersionCPE
emccelerra_network_server6.0.36.4cpe:2.3:a:emc:celerra_network_server:6.0.36.4:*:*:*:*:*:*:*
emccelerra_network_server6.0.60.2cpe:2.3:a:emc:celerra_network_server:6.0.60.2:*:*:*:*:*:*:*
emcvnx7.0.12.0cpe:2.3:a:emc:vnx:7.0.12.0:*:*:*:*:*:*:*
emcvnx7.0.53.1cpe:2.3:a:emc:vnx:7.0.53.1:*:*:*:*:*:*:*
emcvnxe2.0cpe:2.3:a:emc:vnxe:2.0:*:*:*:*:*:*:*
emcvnxe2.0cpe:2.3:a:emc:vnxe:2.0:sp1:*:*:*:*:*:*
emcvnxe2.0cpe:2.3:a:emc:vnxe:2.0:sp2:*:*:*:*:*:*
emcvnxe2.0cpe:2.3:a:emc:vnxe:2.0:sp3:*:*:*:*:*:*
emcvnxemr1cpe:2.3:a:emc:vnxe:mr1:sp1:*:*:*:*:*:*
emcvnxemr1cpe:2.3:a:emc:vnxe:mr1:sp2:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

56.3%

Related for CVE-2012-2282