CVE-2016-9868: Medium severity dell emc scaleio vulnerability
Published Jan 6, 2017
·Updated
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may cause a denial-of-service by generating a kernel panic in the SCINI driver using IOCTL calls which may render the ScaleIO Data Client (SDC) server unavailable until the next reboot.
Affected Software
1 affected component
EMC ScaleIO<=2.0.1.0
Event History
Jan 6, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9868?
CVE-2016-9868 is classified as a low-severity vulnerability because it requires local access to exploit.
2
How do I fix CVE-2016-9868?
To fix CVE-2016-9868, upgrade EMC ScaleIO to version 2.0.1.1 or later.
3
What type of attack is associated with CVE-2016-9868?
CVE-2016-9868 is associated with a denial-of-service attack that can cause a kernel panic.
4
Who can exploit CVE-2016-9868?
CVE-2016-9868 can be exploited by a low-privileged local attacker.
5
What does CVE-2016-9868 affect?
CVE-2016-9868 affects EMC ScaleIO versions prior to 2.0.1.1.