First published: Thu Aug 05 2010(Updated: )
The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for an intranet network within the appliance, which allows remote attackers to read, create, or modify arbitrary files in the user data directory via NFS requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Celerra Network Attached Storage |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2860 is classified as a critical vulnerability due to the potential for unauthorized access to sensitive user data.
To mitigate CVE-2010-2860, it is recommended to apply the latest security patches and restrict external network access to the EMC Celerra Network Attached Storage.
CVE-2010-2860 affects the EMC Celerra Network Attached Storage appliances.
CVE-2010-2860 can be exploited through NFS requests, allowing remote attackers to manipulate files in the user data directory.
A possible workaround for CVE-2010-2860 includes configuring firewall rules to block unauthorized access to the internal IP addresses of the EMC Celerra appliance.