Lucene search

K
cve[email protected]CVE-2016-0917
HistorySep 21, 2016 - 2:59 a.m.

CVE-2016-0917

2016-09-2102:59:05
CWE-264
web.nvd.nist.gov
23
4
cve-2016-0917
smb service
emc vnxe
vnx1
vnx2
celerra
ntlm challenge-response
arbitrary code
remote attackers
authentication requests

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.6 High

AI Score

Confidence

High

0.962 High

EPSS

Percentile

99.5%

The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does not prevent duplicate NTLM challenge-response nonces, which makes it easier for remote attackers to execute arbitrary code, or read or write to files, via a series of authentication requests, a related issue to CVE-2010-0231.

Affected configurations

NVD
Node
emcvnx1_oe_firmwareMatch-
OR
emcvnx2_oe_firmwareMatch-
OR
emcvnxe_oe_firmwareMatch-
AND
emcvnx5200Match-
OR
emcvnx5400Match-
OR
emcvnx5600Match-
OR
emcvnx5800Match-
OR
emcvnxe1600Match-
OR
emcvnxe3100Match-
OR
emcvnxe3150Match-
OR
emcvnxe3200Match-
OR
emcvnxe3200_hybridMatch-
OR
emcvnxe3300Match-

Social References

More

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.6 High

AI Score

Confidence

High

0.962 High

EPSS

Percentile

99.5%