CVE-2015-6848
Last modified
CVE-2015-6848 is a vulnerability of currently unknown severity. EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not universally present, allows remote authenticated AD users to obtain root privileges via unspecified vectors.. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not universally present, allows remote authenticated AD users to obtain root privileges via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emc | Isilon Onefs | <= 7.1.1.0 |
| Emc | Isilon Onefs | 7.1.1.1 |
| Emc | Isilon Onefs | 7.1.1.2 |
| Emc | Isilon Onefs | 7.1.1.3 |
| Emc | Isilon Onefs | 7.1.1.4 |
| Emc | Isilon Onefs | 7.2.0.0 |
| Emc | Isilon Onefs | 7.2.0.1 |
| Emc | Isilon Onefs | 7.2.0.2 |
| Emc | Isilon Onefs | 7.2.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-6848?
How severe is CVE-2015-6848?
How do I fix CVE-2015-6848?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-6839The parse function in MSA vot.Ar 3.1 does not check whether …
- CVE-2015-6843Reviewer in EMC SourceOne Email Supervisor before 7.2 does n…
- CVE-2015-6844Cross-site scripting (XSS) vulnerability in Reviewer in EMC …
- CVE-2015-6845EMC SourceOne Email Supervisor before 7.2 does not properly …
- CVE-2015-6846EMC SourceOne Email Supervisor before 7.2 uses hardcoded enc…
- CVE-2015-6847The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 …
- CVE-2015-6849EMC NetWorker before 8.0.4.5, 8.1.x before 8.1.3.6, 8.2.x be…
- CVE-2015-6850EMC VPLEX GeoSynchrony 5.4 SP1 before P3 and 5.5 before Patc…
- CVE-2015-6851EMC RSA SecurID Web Agent before 8.0 allows physically proxi…
- CVE-2015-6852Directory traversal vulnerability in the API in EMC Secure R…
- CVE-2015-6853The Domino web agent in CA Single Sign-On (aka SSO, formerly…
- CVE-2015-6854The non-Domino web agents in CA Single Sign-On (aka SSO, for…
Are you affected by CVE-2015-6848?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
