{"api_version":"1","generated_at":"2026-07-23T05:43:43+00:00","cve":"CVE-2015-6848","urls":{"html":"https://cve.report/CVE-2015-6848","api":"https://cve.report/api/cve/CVE-2015-6848.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-6848","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-6848"},"summary":{"title":"CVE-2015-6848","description":"EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not universally present, allows remote authenticated AD users to obtain root privileges via unspecified vectors.","state":"PUBLISHED","assigner":"dell","published_at":"2015-11-27 02:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-284","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.5","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://seclists.org/bugtraq/2015/Nov/121","name":"http://seclists.org/bugtraq/2015/Nov/121","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bugtraq: ESA-2015-164: EMC Isilon OneFS Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-6848","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-6848","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"6848","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"emc","cpe5":"isilon_onefs","cpe6":"7.1.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6848","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"emc","cpe5":"isilon_onefs","cpe6":"7.1.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6848","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"emc","cpe5":"isilon_onefs","cpe6":"7.1.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6848","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"emc","cpe5":"isilon_onefs","cpe6":"7.1.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6848","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"emc","cpe5":"isilon_onefs","cpe6":"7.2.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6848","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"emc","cpe5":"isilon_onefs","cpe6":"7.2.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6848","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"emc","cpe5":"isilon_onefs","cpe6":"7.2.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6848","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"emc","cpe5":"isilon_onefs","cpe6":"7.2.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6848","vulnerable":"1","versionEndIncluding":"7.1.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"emc","cpe5":"isilon_onefs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T07:36:34.178Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20151124 ESA-2015-164: EMC Isilon OneFS Privilege Escalation Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://seclists.org/bugtraq/2015/Nov/121"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-11-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not universally present, allows remote authenticated AD users to obtain root privileges via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-11-27T02:57:01.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"20151124 ESA-2015-164: EMC Isilon OneFS Privilege Escalation Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://seclists.org/bugtraq/2015/Nov/121"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2015-6848","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not universally present, allows remote authenticated AD users to obtain root privileges via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20151124 ESA-2015-164: EMC Isilon OneFS Privilege Escalation Vulnerability","refsource":"BUGTRAQ","url":"http://seclists.org/bugtraq/2015/Nov/121"}]}}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2015-6848","datePublished":"2015-11-27T02:00:00.000Z","dateReserved":"2015-09-10T00:00:00.000Z","dateUpdated":"2024-08-06T07:36:34.178Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-11-27 02:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-284","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:emc:isilon_onefs:*:*:*:*:*:*:*:*","versionEndIncluding":"7.1.1.0","matchCriteriaId":"6DBE16CA-46F6-4E5C-B361-67074B1771F1"},{"vulnerable":true,"criteria":"cpe:2.3:o:emc:isilon_onefs:7.1.1.1:*:*:*:*:*:*:*","matchCriteriaId":"A669BE6B-726F-4F34-A009-798E32FF6895"},{"vulnerable":true,"criteria":"cpe:2.3:o:emc:isilon_onefs:7.1.1.2:*:*:*:*:*:*:*","matchCriteriaId":"4AE74624-A44D-4837-AD36-DBF3E93D5ED9"},{"vulnerable":true,"criteria":"cpe:2.3:o:emc:isilon_onefs:7.1.1.3:*:*:*:*:*:*:*","matchCriteriaId":"47CBA2E5-6E46-4922-B56B-3F8C578074B1"},{"vulnerable":true,"criteria":"cpe:2.3:o:emc:isilon_onefs:7.1.1.4:*:*:*:*:*:*:*","matchCriteriaId":"90C22C93-9069-406E-9A14-03F20AD34D11"},{"vulnerable":true,"criteria":"cpe:2.3:o:emc:isilon_onefs:7.2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"0E8AF3E1-FE57-40B9-95DD-4E4C8EB578CB"},{"vulnerable":true,"criteria":"cpe:2.3:o:emc:isilon_onefs:7.2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"7F551F88-3176-4E92-AE7A-FCAB3A220A45"},{"vulnerable":true,"criteria":"cpe:2.3:o:emc:isilon_onefs:7.2.0.2:*:*:*:*:*:*:*","matchCriteriaId":"26144325-6722-48C1-A0C2-BB78EF9BDE60"},{"vulnerable":true,"criteria":"cpe:2.3:o:emc:isilon_onefs:7.2.1.0:*:*:*:*:*:*:*","matchCriteriaId":"10B1B998-AEEE-4123-82F3-72D84EF681DC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"6848","Ordinal":"1","Title":"CVE-2015-6848","CVE":"CVE-2015-6848","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"6848","Ordinal":"1","NoteData":"EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not universally present, allows remote authenticated AD users to obtain root privileges via unspecified vectors.","Type":"Description","Title":"CVE-2015-6848"},{"CveYear":"2015","CveId":"6848","Ordinal":"2","NoteData":"2015-11-26","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"6848","Ordinal":"3","NoteData":"2015-11-26","Type":"Other","Title":"Modified"}]}}}