EMC Celerra Unified Storage Platform NAS Security Bypass Vulnerability
BID:42134
Info
EMC Celerra Unified Storage Platform NAS Security Bypass Vulnerability
| Bugtraq ID: | 42134 |
| Class: | Design Error |
| CVE: |
CVE-2010-2860 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2010 12:00AM |
| Updated: | Sep 09 2010 11:43AM |
| Credit: | Steve Ocepek of Trustwave's SpiderLabs |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
EMC Celerra Unified Storage Platform NAS Security Bypass Vulnerability
EMC Celerra Unified Storage Platform is prone to a security-bypass vulnerability.
A successful exploit will result in an attacker gaining access to the contents of the data directory of the NFS server.
EMC Celerra Unified Storage Platform is prone to a security-bypass vulnerability.
A successful exploit will result in an attacker gaining access to the contents of the data directory of the NFS server.
Exploit / POC
EMC Celerra Unified Storage Platform NAS Security Bypass Vulnerability
An attacker can exploit this issue by using readily available tools.
An attacker can exploit this issue by using readily available tools.
Solution / Fix
EMC Celerra Unified Storage Platform NAS Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
EMC Celerra Unified Storage Platform NAS Security Bypass Vulnerability
References:
References:
- Unauthorized access to root NFS export on EMC Celerra Network Attached Storage ( (EMC)
- [email protected] (ESA-2010-015: EMC Celerra NFS authentication bypass vulnerability using IP spoo)