CVE-2016-0917 (vnx1_oe_firmware, vnx2_oe_firmware, vnxe_oe_firmware)

CVE-2016-0917 (vnx1_oe_firmware, vnx2_oe_firmware, vnxe_oe_firmware)

The SMB service in EMC VNXe, VNX1 File OE before 7.1.80.3, and VNX2 File OE before 8.1.9.155 does not prevent duplicate NTLM challenge-response nonces, which makes it easier for remote attackers to execute arbitrary code, or read or write to files, via a series of authentication requests, a related issue to CVE-2010-0231.

Source: CVE-2016-0917 (vnx1_oe_firmware, vnx2_oe_firmware, vnxe_oe_firmware)

CVE-2016-0917

CVE-2016-0917

The SMB service in EMC VNXe, VNX1 File OE before 7.1.80.3, and VNX2 File OE before 8.1.9.155 does not prevent duplicate NTLM challenge-response nonces, which makes it easier for remote attackers to execute arbitrary code, or read or write to files, via a series of authentication requests, a related issue to CVE-2010-0231.

Source: CVE-2016-0917

CVE-2016-0904 (avamar_server)

CVE-2016-0904 (avamar_server)

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers’ installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.

Source: CVE-2016-0904 (avamar_server)

CVE-2016-0904

CVE-2016-0904

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers’ installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.

Source: CVE-2016-0904