CVE-2012-2282
Summary
| CVE | CVE-2012-2282 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-07-16 20:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | EMC Celerra Network Server 6.x before 6.0.61.0, VNX 7.x before 7.0.53.2, and VNXe 2.0 and 2.1 before 2.1.3.19077 (aka MR1 SP3.2) and 2.2 before 2.2.0.19078 (aka MR2 SP0.2) do not properly implement NFS access control, which allows remote authenticated users to read or modify files via a (1) NFSv2, (2) NFSv3, or (3) NFSv4 request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Celerra Network Server | 6.0.36.4 | All | All | All |
| Application | Emc | Celerra Network Server | 6.0.60.2 | All | All | All |
| Application | Emc | Vnx | 7.0.12.0 | All | All | All |
| Application | Emc | Vnx | 7.0.53.1 | All | All | All |
| Application | Emc | Vnxe | 2.0 | All | All | All |
| Application | Emc | Vnxe | 2.0 | sp1 | All | All |
| Application | Emc | Vnxe | 2.0 | sp2 | All | All |
| Application | Emc | Vnxe | 2.0 | sp3 | All | All |
| Application | Emc | Vnxe | mr1 | sp1 | All | All |
| Application | Emc | Vnxe | mr1 | sp2 | All | All |
| Application | Emc | Vnxe | mr1 | sp3 | All | All |
| Application | Emc | Vnxe | mr1 | sp3.1 | All | All |
| Application | Emc | Vnxe | mr2 | sp0.1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EMC Celerra/VNX/VNXe Access Control Bug Lets Remote Authenticated Users Access Files/Directories - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| archives.neohapsis.com/archives/bugtraq/2012-07/0063.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.