5.9

CVE-2016-0907

EMC Isilon OneFS 7.1.x and 7.2.x before 7.2.1.3 and 8.0.x before 8.0.0.1, and IsilonSD Edge OneFS 8.0.x before 8.0.0.1, does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream, a similar issue to CVE-2016-2115.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EmcIsilon Onefs Version7.1.0.0
EmcIsilon Onefs Version7.1.0.1
EmcIsilon Onefs Version7.1.0.2
EmcIsilon Onefs Version7.1.0.3
EmcIsilon Onefs Version7.1.0.4
EmcIsilon Onefs Version7.1.0.5
EmcIsilon Onefs Version7.1.0.6
EmcIsilon Onefs Version7.1.1.0
EmcIsilon Onefs Version7.1.1.1
EmcIsilon Onefs Version7.1.1.2
EmcIsilon Onefs Version7.1.1.3
EmcIsilon Onefs Version7.1.1.4
EmcIsilon Onefs Version7.1.1.5
EmcIsilon Onefs Version7.1.1.6
EmcIsilon Onefs Version7.1.1.7
EmcIsilon Onefs Version7.1.1.8
EmcIsilon Onefs Version7.1.1.9
EmcIsilon Onefs Version7.2.0.0
EmcIsilon Onefs Version7.2.1.0
EmcIsilon Onefs Version7.2.1.1
EmcIsilon Onefs Version7.2.1.2
EmcIsilon Onefs Version8.0.0.0
EmcIsilonsd Edge Onefs Version8.0.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.467
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N