« Volver al listado

CVE-2016-0910

Estado: ModificadaAlta (8.8)—

EMC Data Domain OS 5.5 before 5.5.4.0, 5.6 before 5.6.1.004, and 5.7 before 5.7.2.0 stores session identifiers of GUI users in a world-readable file, which allows local users to hijack arbitrary accounts via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-0910",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-06-10T01:59:01.537",
  "references": [
    {
      "url": "http://seclists.org/bugtraq/2016/Jun/44",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1036074",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://seclists.org/bugtraq/2016/Jun/44",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1036074",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "EMC Data Domain OS 5.5 before 5.5.4.0, 5.6 before 5.6.1.004, and 5.7 before 5.7.2.0 stores session identifiers of GUI users in a world-readable file, which allows local users to hijack arbitrary accounts via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "EMC Data Domain OS 5.5 en versiones anteriores a 5.5.4.0, 5.6 en versiones anteriores a 5.6.1.004 y 5.7 en versiones anteriores a 5.7.2.0 almacena identificadores de sesión de usuarios GUI en un archivo de lectura para todos, lo que permite a usuarios locales secuestrar cuentas arbitrarias a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:38:27.370",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:emc:data_domain_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FADA326-7009-407A-8028-BB5E027D3387",
              "versionEndIncluding": "5.5.3.3"
            },
            {
              "criteria": "cpe:2.3:o:emc:data_domain_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AF2A431-22BF-4CA9-BC88-2745E769AEEC",
              "versionEndIncluding": "5.6.1.0"
            },
            {
              "criteria": "cpe:2.3:o:emc:data_domain_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9357ECCA-79F2-4FC3-9C40-FE060A6F0030",
              "versionEndIncluding": "5.7.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}