CVE-2016-0917
The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does not prevent duplicate NTLM challenge-response nonces, which makes it easier for remote attackers to execute arbitrary code, or read or write to files, via a series of authentication requests, a related issue to CVE-2010-0231.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.18% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- emc/vnx1 oe firmware · emc/vnx2 oe firmware · emc/vnxe oe firmware
- Source
- security_alert@emc.com
References
- http://seclists.org/bugtraq/2016/Sep/32Third Party Advisory
- http://www.securityfocus.com/archive/1/539993/30/0/threaded
- http://www.securityfocus.com/bid/93023
- http://www.securitytracker.com/id/1036843
- http://seclists.org/bugtraq/2016/Sep/32Third Party Advisory
- http://www.securityfocus.com/archive/1/539993/30/0/threaded
- http://www.securityfocus.com/bid/93023
- http://www.securitytracker.com/id/1036843
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.