Lucene search

K
cvelistIbmCVELIST:CVE-2018-1668
HistoryJan 29, 2019 - 4:00 p.m.

CVE-2018-1668

2019-01-2916:00:00
ibm
www.cve.org
8

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

45.7%

IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows “null” logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.

CNA Affected

[
  {
    "product": "DataPower Gateway",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "7.6.0.0"
      },
      {
        "status": "affected",
        "version": "7.5.2.0"
      },
      {
        "status": "affected",
        "version": "7.5.1.0"
      },
      {
        "status": "affected",
        "version": "7.5.0.0"
      },
      {
        "status": "affected",
        "version": "7.5.0.19"
      },
      {
        "status": "affected",
        "version": "7.5.1.18"
      },
      {
        "status": "affected",
        "version": "7.5.2.18"
      },
      {
        "status": "affected",
        "version": "7.6.0.11"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

45.7%

Related for CVELIST:CVE-2018-1668