Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-2282


Vulnerability Score 6.5 6.5
CVE Id CVE-2012-2282
Last Modified 21 Mar 2013 11:10:16
Published 16 Jul 2012 04:55:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE



EMC Celerra Network Server 6.x before, VNX 7.x before, and VNXe 2.0 and 2.1 before (aka MR1 SP3.2) and 2.2 before (aka MR2 SP0.2) do not properly implement NFS access control, which allows remote authenticated users to read or modify files via a (1) NFSv2, (2) NFSv3, or (3) NFSv4 request.

Vulnerable Systems


  • Emc Celerra Network Server

  • Emc Celerra Network Server

  • Emc Vnx

  • Emc Vnx

  • Emc Vnxe 2.0

  • Emc Vnxe Mr1

  • Emc Vnxe Mr2


BUGTRAQ - 20120711 ESA-2012-027: EMC Celerra/VNX/VNXe Improper Access Control Vulnerability

SECTRACK - 1027242

Last Updated: 27 May 2016 10:57:33