Lucene search

K
ibmIBM12F1179C56D80116F921BC7AA01DC1536E5D4133826759CAB6CCA45F95E88CE5
HistorySep 26, 2022 - 10:21 p.m.

Security bulletin: Authentication bypass vulnerability in IBM SAN Volume Controller and Storwize Family (CVE-2012-6354)

2022-09-2622:21:32
www.ibm.com
29
ibm
san volume controller
storwize family
authentication bypass
vulnerability
cve-2012-6354
cvss
superuser privilege
configuration modification
remediation
ptf
workaround
mitigation
x-force vulnerability database
marcin mielnoczek
narodowe archiwum cyfrowe

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.005 Low

EPSS

Percentile

76.1%

Abstract

Administrative access to the system via the GUI may be obtained without supplying proper credentials.

Content

VULNERABILITY DETAILS

CVE** ID:**

CVE-2012-6354

DESCRIPTION:

The vulnerability can be exploited by a user with access to the systemโ€™s management IP interface. If successful the user can gain access with superuser privilege which will allow any modification to the configuration, including complete deletion.

CVSS:
CVSS Base Score: 7.5
CVSS Temporal Score: See <http://xforce.iss.net/xforce/xfdb/80716&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

AFFECTED PRODUCTS:

IBM SAN Volume Controller
IBM Storwize V7000
IBM Storwize V3500
IBM Storwize V3700
IBM Flex System V7000

REMEDIATION:

For IBM SAN Volume Controller and IBM Storwize V7000 install PTF level 7.1.0.1, 6.4.1.3, 6.3.0.7 or 6.2.0.6.

For IBM Storwize V3700 and V3500, and IBM Flex System V7000 install PTF level 7.1.0.1 or 6.4.1.3.

Workaround(s):
None

Mitigation(s):
Access to the systemโ€™s IP interface can be restricted, for example using a private network or firewall technology.** **
REFE****RENCES:****_
_
_ยท _Complete CVSS Guide_
_ยท _On-line Calculator V2 __
__ยท ___CVE-2012-6354 __
ยท _X-Force Vulnerability Database _http://xforce.iss.net/xforce/xfdb/80716


RELATED INFORMATION:

none

ACKNOWLEDGEMENT:

Vulnerability reported by Marcin Mielnoczek of Narodowe Archiwum Cyfrowe (National Digital Archives)

[{โ€œProductโ€:{โ€œcodeโ€:โ€œST3FR7โ€,โ€œlabelโ€:โ€œIBM Storwize V7000โ€},โ€œBusiness Unitโ€:{โ€œcodeโ€:โ€œBU058โ€,โ€œlabelโ€:โ€œIBM Infrastructure w/TPSโ€},โ€œComponentโ€:โ€œ6.4โ€,โ€œPlatformโ€:[{โ€œcodeโ€:โ€œโ€,โ€œlabelโ€:โ€œIBM Storwize V7000โ€}],โ€œVersionโ€:โ€œ6.1;6.2;6.3;6.4โ€,โ€œEditionโ€:โ€œโ€,โ€œLine of Businessโ€:{โ€œcodeโ€:โ€œLOB26โ€,โ€œlabelโ€:โ€œStorageโ€}},{โ€œProductโ€:{โ€œcodeโ€:โ€œSTPVGUโ€,โ€œlabelโ€:โ€œSAN Volume Controllerโ€},โ€œBusiness Unitโ€:{โ€œcodeโ€:โ€œBU058โ€,โ€œlabelโ€:โ€œIBM Infrastructure w/TPSโ€},โ€œComponentโ€:โ€œ6.4โ€,โ€œPlatformโ€:[{โ€œcodeโ€:โ€œโ€,โ€œlabelโ€:โ€œSAN Volume Controllerโ€}],โ€œVersionโ€:โ€œ6.1;6.2;6.3;6.4โ€,โ€œEditionโ€:โ€œโ€,โ€œLine of Businessโ€:{โ€œcodeโ€:โ€œLOB26โ€,โ€œlabelโ€:โ€œStorageโ€}},{โ€œProductโ€:{โ€œcodeโ€:โ€œSTLM6Bโ€,โ€œlabelโ€:โ€œIBM Storwize V3500 (2071)โ€},โ€œBusiness Unitโ€:{โ€œcodeโ€:โ€œBU058โ€,โ€œlabelโ€:โ€œIBM Infrastructure w/TPSโ€},โ€œComponentโ€:โ€œ6.4โ€,โ€œPlatformโ€:[{โ€œcodeโ€:โ€œPF025โ€,โ€œlabelโ€:โ€œPlatform Independentโ€}],โ€œVersionโ€:โ€œ6.4โ€,โ€œEditionโ€:โ€œโ€,โ€œLine of Businessโ€:{โ€œcodeโ€:โ€œLOB26โ€,โ€œlabelโ€:โ€œStorageโ€}},{โ€œProductโ€:{โ€œcodeโ€:โ€œSTLM5Aโ€,โ€œlabelโ€:โ€œIBM Storwize V3700 (2072)โ€},โ€œBusiness Unitโ€:{โ€œcodeโ€:โ€œBU058โ€,โ€œlabelโ€:โ€œIBM Infrastructure w/TPSโ€},โ€œComponentโ€:โ€œ6.4โ€,โ€œPlatformโ€:[{โ€œcodeโ€:โ€œPF025โ€,โ€œlabelโ€:โ€œPlatform Independentโ€}],โ€œVersionโ€:โ€œNot Applicableโ€,โ€œEditionโ€:โ€œโ€,โ€œLine of Businessโ€:{โ€œcodeโ€:โ€œLOB26โ€,โ€œlabelโ€:โ€œStorageโ€}}]

Affected configurations

Vulners
Node
ibmstorwize_v7000Match6.1
OR
ibmstorwize_v7000Match6.2
OR
ibmstorwize_v7000Match6.3
OR
ibmstorwize_v7000Match6.4
OR
ibmsan_volume_controllerMatch6.1
OR
ibmsan_volume_controllerMatch6.2
OR
ibmsan_volume_controllerMatch6.3
OR
ibmsan_volume_controllerMatch6.4
OR
ibmstorwize_v3500_softwareMatch6.4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.005 Low

EPSS

Percentile

76.1%

Related for 12F1179C56D80116F921BC7AA01DC1536E5D4133826759CAB6CCA45F95E88CE5