CVE-2016-0907: Medium severity dell emc isilon onefs vulnerability
EMC Isilon OneFS 7.1.x and 7.2.x before 7.2.1.3 and 8.0.x before 8.0.0.1, and IsilonSD Edge OneFS 8.0.x before 8.0.0.1, does not require SMB signing within a DCERPC session over ncacnnp, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream, a similar issue to CVE-2016-2115.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0907?
CVE-2016-0907 has been assigned a severity rating of high due to its potential for exploitation by man-in-the-middle attacks.
How do I fix CVE-2016-0907?
To remedy CVE-2016-0907, upgrade your EMC Isilon OneFS to version 7.2.1.3 or later, or to version 8.0.0.1 or later.
Which versions of Isilon are affected by CVE-2016-0907?
CVE-2016-0907 affects EMC Isilon OneFS versions 7.1.x, 7.2.x prior to 7.2.1.3 and 8.0.x prior to 8.0.0.1.
What type of vulnerability is CVE-2016-0907?
CVE-2016-0907 is a security vulnerability related to insufficient SMB signing within DCERPC sessions.
Can CVE-2016-0907 lead to data breaches?
Yes, if exploited, CVE-2016-0907 can allow attackers to spoof SMB clients, potentially leading to data breaches.