CVE-2016-0917: Critical severity emc vnx1 firmware vulnerability
The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does not prevent duplicate NTLM challenge-response nonces, which makes it easier for remote attackers to execute arbitrary code, or read or write to files, via a series of authentication requests, a related issue to CVE-2010-0231.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0917?
CVE-2016-0917 has a high severity rating due to its potential to allow unauthorized access through NTLM challenge-response vulnerabilities.
How do I fix CVE-2016-0917?
To fix CVE-2016-0917, upgrade the affected EMC VNXe or VNX firmware to the latest available version that addresses this vulnerability.
What systems are affected by CVE-2016-0917?
CVE-2016-0917 affects EMC VNXe3200, VNXe3100/3150/3300, VNX1 File OE, VNX2 File OE and all versions of Celerra.
What type of vulnerability is CVE-2016-0917?
CVE-2016-0917 is a security vulnerability related to improper handling of NTLM authentication in the SMB service.
Is there a workaround for CVE-2016-0917?
There is no official workaround for CVE-2016-0917; the recommended solution is to apply the firmware updates as soon as possible.