Lucene search

K
ibmIBMA4B0110C8DB3C61E08710BED2B55C82B1CF38992F23032B0CCFFCBC36D15AD54
HistorySep 23, 2021 - 1:31 a.m.

Security Bulletin: Vulnerabilities in strongswan affect Power Hardware Management Console (CVE-2015-4171)

2021-09-2301:31:39
www.ibm.com
7

EPSS

0.005

Percentile

76.3%

Summary

Strongswan is used by Power Hardware Management Console (HMC). HMC has addressed the applicable CVEs.

Vulnerability Details

CVEID: CVE-2015-4171**
DESCRIPTION:** strongSwan could allow a remote authenticated attacker to obtain sensitive information, caused by an error in IKEv2 connections related to server authentication with a certificate and EAP or pre-shared keys. An attacker could exploit this vulnerability to obtain user credentials and other sensitive information.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/#/vulnerabilities/103885 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

Affected Products and Versions

Power HMC V7.8.0.0
Power HMC V7.9.0.0
Power HMC V8.1.0.0
Power HMC V8.2.0.0
Power HMC V8.3.0.0
Power HMC V8.4.0.0

Remediation/Fixes

The following fixes are available on IBM Fix Central

Product

|

VRMF

|

APAR

|

Remediation/Fix

—|—|—|—

Power HMC

|

V7.780.0 SP2

|

MB03965

|

Apply eFix MH01570

Power HMC

|

V7.790.0 SP2

|

MB03966

|

Apply eFix MH01571

Power HMC

|

V8.8.1.0 SP2

|

MB03967

|

Apply eFix MH01572

Power HMC

|

V8.8.2.0 SP2

|

MB03968

|

Apply eFix MH01573

Power HMC

|

V8.8.3.0 SP1

|

MB03969

|

Apply eFix MH01574

Power HMC

|

V8.8.4.0

|

MH01559

|

Apply eFix MH01560

Workarounds and Mitigations

None

EPSS

0.005

Percentile

76.3%

Related for A4B0110C8DB3C61E08710BED2B55C82B1CF38992F23032B0CCFFCBC36D15AD54