Lucene search

K
cveIbmCVE-2014-0875
HistoryJul 07, 2014 - 11:01 a.m.

CVE-2014-0875

2014-07-0711:01:29
CWE-264
ibm
web.nvd.nist.gov
27
cve
2014
0875
ibm
storwize
v7000
ace
acl
bypass
nvd
security
vulnerability

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

36.0%

Active Cloud Engine (ACE) in IBM Storwize V7000 Unified 1.3.0.0 through 1.4.3.x allows remote attackers to bypass intended ACL restrictions in opportunistic circumstances by leveraging incorrect ACL synchronization over an unreliable NFS connection that requires retransmissions.

Affected configurations

Nvd
Node
ibmstorwize_unified_v7000_softwareMatch1.3.0.0
OR
ibmstorwize_unified_v7000_softwareMatch1.3.1.0
OR
ibmstorwize_unified_v7000_softwareMatch1.4.0.0
OR
ibmstorwize_unified_v7000_softwareMatch1.4.0.1
OR
ibmstorwize_unified_v7000_softwareMatch1.4.0.2
OR
ibmstorwize_unified_v7000_softwareMatch1.4.0.3
OR
ibmstorwize_unified_v7000_softwareMatch1.4.0.4
OR
ibmstorwize_unified_v7000_softwareMatch1.4.0.5
OR
ibmstorwize_unified_v7000_softwareMatch1.4.1.0
OR
ibmstorwize_unified_v7000_softwareMatch1.4.1.1
OR
ibmstorwize_unified_v7000_softwareMatch1.4.2.0
OR
ibmstorwize_unified_v7000_softwareMatch1.4.2.1
OR
ibmstorwize_unified_v7000_softwareMatch1.4.3.0
OR
ibmstorwize_unified_v7000_softwareMatch1.4.3.1
OR
ibmstorwize_unified_v7000_softwareMatch1.4.3.2
AND
ibmstorwize_unified_v7000Match-
VendorProductVersionCPE
ibmstorwize_unified_v7000_software1.3.0.0cpe:2.3:a:ibm:storwize_unified_v7000_software:1.3.0.0:*:*:*:*:*:*:*
ibmstorwize_unified_v7000_software1.3.1.0cpe:2.3:a:ibm:storwize_unified_v7000_software:1.3.1.0:*:*:*:*:*:*:*
ibmstorwize_unified_v7000_software1.4.0.0cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.0:*:*:*:*:*:*:*
ibmstorwize_unified_v7000_software1.4.0.1cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.1:*:*:*:*:*:*:*
ibmstorwize_unified_v7000_software1.4.0.2cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.2:*:*:*:*:*:*:*
ibmstorwize_unified_v7000_software1.4.0.3cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.3:*:*:*:*:*:*:*
ibmstorwize_unified_v7000_software1.4.0.4cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.4:*:*:*:*:*:*:*
ibmstorwize_unified_v7000_software1.4.0.5cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.5:*:*:*:*:*:*:*
ibmstorwize_unified_v7000_software1.4.1.0cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.1.0:*:*:*:*:*:*:*
ibmstorwize_unified_v7000_software1.4.1.1cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.1.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

36.0%

Related for CVE-2014-0875