Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-2282

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2012-2282
Last Modified 21 Mar 2013 11:10:16
Published 16 Jul 2012 04:55:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2012-2282

Summary

EMC Celerra Network Server 6.x before 6.0.61.0, VNX 7.x before 7.0.53.2, and VNXe 2.0 and 2.1 before 2.1.3.19077 (aka MR1 SP3.2) and 2.2 before 2.2.0.19078 (aka MR2 SP0.2) do not properly implement NFS access control, which allows remote authenticated users to read or modify files via a (1) NFSv2, (2) NFSv3, or (3) NFSv4 request.

Vulnerable Systems

Application

  • Emc Celerra Network Server 6.0.36.4

  • Emc Celerra Network Server 6.0.60.2

  • Emc Vnx 7.0.12.0

  • Emc Vnx 7.0.53.1

  • Emc Vnxe 2.0

  • Emc Vnxe Mr1

  • Emc Vnxe Mr2


References

BUGTRAQ - 20120711 ESA-2012-027: EMC Celerra/VNX/VNXe Improper Access Control Vulnerability

SECTRACK - 1027242


Last Updated: 27 May 2016 10:57:33