Description
The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does not prevent duplicate NTLM challenge-response nonces, which makes it easier for remote attackers to execute arbitrary code, or read or write to files, via a series of authentication requests, a related issue to CVE-2010-0231.
Published: 2016-09-21
Score: 9.8 Critical
EPSS: 4.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-0928 The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does not prevent duplicate NTLM challenge-response nonces, which makes it easier for remote attackers to execute arbitrary code, or read or write to files, via a series of authentication requests, a related issue to CVE-2010-0231.
History

No history.

Subscriptions

Emc Vnx1 Oe Firmware Vnx2 Oe Firmware Vnx5200 Vnx5400 Vnx5600 Vnx5800 Vnxe1600 Vnxe3100 Vnxe3150 Vnxe3200 Vnxe3200 Hybrid Vnxe3300 Vnxe Oe Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-08-05T22:38:41.107Z

Reserved: 2015-12-17T00:00:00.000Z

Link: CVE-2016-0917

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-09-21T02:59:05.663

Modified: 2026-05-06T22:30:45.220

Link: CVE-2016-0917

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses