CVE Vulnerabilities

CVE-2016-0907

Published: May 30, 2016 | Modified: Apr 12, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

EMC Isilon OneFS 7.1.x and 7.2.x before 7.2.1.3 and 8.0.x before 8.0.0.1, and IsilonSD Edge OneFS 8.0.x before 8.0.0.1, does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream, a similar issue to CVE-2016-2115.

Affected Software

NameVendorStart VersionEnd Version
Isilon_onefsEmc7.1.0.0 (including)7.1.0.0 (including)
Isilon_onefsEmc7.1.0.1 (including)7.1.0.1 (including)
Isilon_onefsEmc7.1.0.2 (including)7.1.0.2 (including)
Isilon_onefsEmc7.1.0.3 (including)7.1.0.3 (including)
Isilon_onefsEmc7.1.0.4 (including)7.1.0.4 (including)
Isilon_onefsEmc7.1.0.5 (including)7.1.0.5 (including)
Isilon_onefsEmc7.1.0.6 (including)7.1.0.6 (including)
Isilon_onefsEmc7.1.1.0 (including)7.1.1.0 (including)
Isilon_onefsEmc7.1.1.1 (including)7.1.1.1 (including)
Isilon_onefsEmc7.1.1.2 (including)7.1.1.2 (including)
Isilon_onefsEmc7.1.1.3 (including)7.1.1.3 (including)
Isilon_onefsEmc7.1.1.4 (including)7.1.1.4 (including)
Isilon_onefsEmc7.1.1.5 (including)7.1.1.5 (including)
Isilon_onefsEmc7.1.1.6 (including)7.1.1.6 (including)
Isilon_onefsEmc7.1.1.7 (including)7.1.1.7 (including)
Isilon_onefsEmc7.1.1.8 (including)7.1.1.8 (including)
Isilon_onefsEmc7.1.1.9 (including)7.1.1.9 (including)
Isilon_onefsEmc7.2.0.0 (including)7.2.0.0 (including)
Isilon_onefsEmc7.2.1.0 (including)7.2.1.0 (including)
Isilon_onefsEmc7.2.1.1 (including)7.2.1.1 (including)
Isilon_onefsEmc7.2.1.2 (including)7.2.1.2 (including)
Isilon_onefsEmc8.0.0.0 (including)8.0.0.0 (including)
Isilonsd_edge_onefsEmc8.0.0.0 (including)8.0.0.0 (including)

References