Lucene search

K
cvelistIbmCVELIST:CVE-2022-43873
HistoryFeb 22, 2023 - 5:32 p.m.

CVE-2022-43873 IBM Spectrum Virtualize privilege escalation

2023-02-2217:32:31
ibm
www.cve.org
3
ibm spectrum virtualize
privilege escalation
authenticated user
gui
code execution

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

46.0%

An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute code and escalate their privilege on the system. IBM X-Force ID: 239847.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Spectrum Virtualize",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "8.2, 8.3, 8.4, 8.5"
      }
    ]
  }
]

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

46.0%

Related for CVELIST:CVE-2022-43873