CVE-2010-2860 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 4.3% (pctl 91)
Patch early
A public exploit exists.
Description
The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for an intranet network within the appliance, which allows remote attackers to read, create, or modify arbitrary files in the user data directory via NFS requests.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 4.27% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-08-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| emc | celerra network attached storage |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | EMC Celerra NAS Appliance - Unauthorized Access to Root NFS Export | 2010-08-03 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2010-08/0018.html
- http://securitytracker.com/id?1024271
- http://www.exploit-db.com/exploits/14536
- http://www.securityfocus.com/archive/1/512823/100/0/threaded
- http://www.securityfocus.com/archive/1/513564/100/0/threaded
- http://www.securityfocus.com/bid/42134
- http://www.vupen.com/english/advisories/2010/2337
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60885
- https://www.trustwave.com/spiderlabs/advisories/TWSL2010-003.txt
- http://archives.neohapsis.com/archives/fulldisclosure/2010-08/0018.html
- http://securitytracker.com/id?1024271
- http://www.exploit-db.com/exploits/14536
- http://www.securityfocus.com/archive/1/512823/100/0/threaded
- http://www.securityfocus.com/archive/1/513564/100/0/threaded
- http://www.securityfocus.com/bid/42134
- http://www.vupen.com/english/advisories/2010/2337
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60885
- https://www.trustwave.com/spiderlabs/advisories/TWSL2010-003.txt
→ the Explorer · watch your stack · NVD