{ "id": "CVE-2017-4980", "sourceIdentifier": "security_alert@emc.com", "published": "2017-03-29T21:59:00.177", "lastModified": "2017-04-10T16:47:03.833", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "EMC Isilon OneFS is affected by a path traversal vulnerability that may potentially be exploited by attackers to compromise the affected system. Affected versions are 7.1.0 - 7.1.1.10, 7.2.0 - 7.2.1.3, and 8.0.0 - 8.0.0.1." }, { "lang": "es", "value": "EMC Isilon OneFS es afectada por una vulnerabilidad de recorrido transversal que potencialmente puede ser explotada por los atacantes para comprometer el sistema afectado. Las versiones afectadas son 7.1.0 - 7.1.1.10, 7.2.0 - 7.2.1.3 y 8.0.0 - 8.0.0.1." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-22" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "E706E435-8E45-4ACB-8BBC-5AC458378D4A" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.0.6:*:*:*:*:*:*:*", "matchCriteriaId": "3FE2D48E-39E8-42E6-8E82-AB9FA0547BAC" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "DEDB97FE-6470-4AFE-A3B0-B664F132A190" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "A669BE6B-726F-4F34-A009-798E32FF6895" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "4AE74624-A44D-4837-AD36-DBF3E93D5ED9" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "47CBA2E5-6E46-4922-B56B-3F8C578074B1" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "90C22C93-9069-406E-9A14-03F20AD34D11" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.5:*:*:*:*:*:*:*", "matchCriteriaId": "CDD30754-489E-42BA-8B51-1FEB5DC30912" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.6:*:*:*:*:*:*:*", "matchCriteriaId": "D92501AC-0588-4051-9568-52074E8A2D33" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.7:*:*:*:*:*:*:*", "matchCriteriaId": "F7407DAA-7740-45B0-BA99-03794C8B1215" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.8:*:*:*:*:*:*:*", "matchCriteriaId": "F7E804DB-40F0-4FBF-8A85-A49767DC4022" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.9:*:*:*:*:*:*:*", "matchCriteriaId": "D645B5EF-4333-48BF-960A-03AA2D624376" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.1.1.10:*:*:*:*:*:*:*", "matchCriteriaId": "302422CE-3C0A-44E6-83ED-51EC65482B40" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.2.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "0E8AF3E1-FE57-40B9-95DD-4E4C8EB578CB" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.2.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "7F551F88-3176-4E92-AE7A-FCAB3A220A45" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.2.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "26144325-6722-48C1-A0C2-BB78EF9BDE60" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.2.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "B87E8EEE-42AA-48B3-ABBE-9CE7FD2C275B" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.2.0.4:*:*:*:*:*:*:*", "matchCriteriaId": "6F09B14D-2C84-47F2-8F7F-6F8DAEFFF106" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.2.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "10B1B998-AEEE-4123-82F3-72D84EF681DC" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.2.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "0828B061-28B4-4AEE-BBB9-AF287B90713C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.2.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "064C487D-517E-4F7B-A182-5DF287477652" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:7.2.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "D1600B1F-C307-457B-BC84-73339A64DF8D" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:8.0.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "AB53E775-7A57-41D2-A93D-5F96D72622D1" }, { "vulnerable": true, "criteria": "cpe:2.3:o:emc:isilon_onefs:8.0.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "A17F44A3-8C09-49EE-8545-51C57F36B801" } ] } ] } ], "references": [ { "url": "http://www.securityfocus.com/archive/1/540338/30/0/threaded", "source": "security_alert@emc.com", "tags": [ "Third Party Advisory", "VDB Entry" ] }, { "url": "http://www.securityfocus.com/bid/97222", "source": "security_alert@emc.com", "tags": [ "Third Party Advisory", "VDB Entry" ] } ] }