Vulnerability Description
The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does not prevent duplicate NTLM challenge-response nonces, which makes it easier for remote attackers to execute arbitrary code, or read or write to files, via a series of authentication requests, a related issue to CVE-2010-0231.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emc | Vnx1 Oe Firmware | - |
| Emc | Vnx2 Oe Firmware | - |
| Emc | Vnxe Oe Firmware | - |
| Emc | Vnx5200 | - |
| Emc | Vnx5400 | - |
| Emc | Vnx5600 | - |
| Emc | Vnx5800 | - |
| Emc | Vnxe1600 | - |
| Emc | Vnxe3100 | - |
| Emc | Vnxe3150 | - |
| Emc | Vnxe3200 | - |
| Emc | Vnxe3200 Hybrid | - |
| Emc | Vnxe3300 | - |
Related Weaknesses (CWE)
References
- http://seclists.org/bugtraq/2016/Sep/32Third Party Advisory
- http://www.securityfocus.com/archive/1/539993/30/0/threaded
- http://www.securityfocus.com/bid/93023
- http://www.securitytracker.com/id/1036843
- http://seclists.org/bugtraq/2016/Sep/32Third Party Advisory
- http://www.securityfocus.com/archive/1/539993/30/0/threaded
- http://www.securityfocus.com/bid/93023
- http://www.securitytracker.com/id/1036843
FAQ
What is CVE-2016-0917?
CVE-2016-0917 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before...
How severe is CVE-2016-0917?
CVE-2016-0917 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-0917?
Check the references section above for vendor advisories and patch information. Affected products include: Emc Vnx1 Oe Firmware, Emc Vnx2 Oe Firmware, Emc Vnxe Oe Firmware, Emc Vnx5200, Emc Vnx5400.