Lucene search

K
ibmIBM211030B63DFACDC062207C9720C07BB4194CB622626EFE87492FB90BE0DDB26C
HistoryMay 15, 2024 - 11:37 p.m.

Security Bulletin: Vulnerability in NX-OS Firmware used by IBM c-type SAN directors and switches.

2024-05-1523:37:18
www.ibm.com
14
ibm
nx-os firmware
san directors
switches
openssl
denial of service
cve-2023-2650
vulnerability
fix

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.9%

Summary

Public disclosed OpenSSL vulnerability in NX-OS Firmware used by IBM c-type SAN directors and switches. The vulnerability has been addressed and can be resolved by applying the NX-OS code level listed below. CVE-2023-2650.

Vulnerability Details

CVEID:CVE-2023-2650
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by a flaw when using OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/256611 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
NX-OS 9.2.1 - 9.4(1)
NX-OS 8.1 - 8.5(1)

Remediation/Fixes

Fixes Version(s)
NX-OS 9.4(1a)

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmrational_software_architect_for_websphere_software\'Match11
CPENameOperatorVersion
ibm support for cisco softwareeq11

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.9%