Vulnerability CVE-2010-2860


Published: 2010-08-05   Modified: 2012-02-13

Description:
The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for an intranet network within the appliance, which allows remote attackers to read, create, or modify arbitrary files in the user data directory via NFS requests.

See advisories in our WLB2 database:
Topic
Author
Date
High
Unauthorized Access to Root NFS Export on EMC Celerra NAS Appliance
Trustwave\'...
05.08.2010

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
EMC -> Celerra network attached storage 

 References:
http://archives.neohapsis.com/archives/fulldisclosure/2010-08/0018.html
http://securitytracker.com/id?1024271
http://www.exploit-db.com/exploits/14536
http://www.securityfocus.com/archive/1/512823/100/0/threaded
http://www.securityfocus.com/archive/1/513564/100/0/threaded
http://www.securityfocus.com/bid/42134
http://www.vupen.com/english/advisories/2010/2337
https://exchange.xforce.ibmcloud.com/vulnerabilities/60885
https://www.trustwave.com/spiderlabs/advisories/TWSL2010-003.txt

Copyright 2024, cxsecurity.com

 

Back to Top