CVE Vulnerabilities

CVE-2017-2765

Improper Authentication

Published: Feb 08, 2017 | Modified: Oct 03, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

EMC Isilon InsightIQ 4.1.0, 4.0.1, 4.0.0, 3.2.2, 3.2.1, 3.2.0, 3.1.1, 3.1.0, 3.0.1, 3.0.0 is affected by an authentication bypass vulnerability that could potentially be exploited by attackers to compromise the affected system.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Isilon_insightiq Emc 3.0.0 (including) 3.0.0 (including)
Isilon_insightiq Emc 3.0.1 (including) 3.0.1 (including)
Isilon_insightiq Emc 3.1.0 (including) 3.1.0 (including)
Isilon_insightiq Emc 3.1.1 (including) 3.1.1 (including)
Isilon_insightiq Emc 3.2.0 (including) 3.2.0 (including)
Isilon_insightiq Emc 3.2.1 (including) 3.2.1 (including)
Isilon_insightiq Emc 3.2.2 (including) 3.2.2 (including)
Isilon_insightiq Emc 4.0.0 (including) 4.0.0 (including)
Isilon_insightiq Emc 4.0.1 (including) 4.0.1 (including)
Isilon_insightiq Emc 4.1.0 (including) 4.1.0 (including)

Potential Mitigations

References