Lucene search

K
ibmIBMA5C6A626E4552035D145B7ABE69B9E7521D0570FDF625AEB0CDD03327112130C
HistoryMar 25, 2023 - 12:48 a.m.

Security Bulletin: Unauthenticated User Could Gain Remote Access to TS3100/TS3200 (CVE-2016-9005)

2023-03-2500:48:46
www.ibm.com
23
ibm
tape library
vulnerability
remote access
cve-2016-9005
password change

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

55.7%

Summary

IBM TS3100/TS3200 Tape Library could allow an unauthenticated user, with access to the company network, to change a user’s password and gain remote access to the system.

Vulnerability Details

CVEID:CVE-2016-9005__ __
DESCRIPTION:
IBM TS3100-TS3200 Tape Library could allow an unauthenticated user, with access to the company network, to change a user’s password and gain remote access to the system.
CVSS Base Score: 8.8
CVSS Temporal Score: See http://exchange.xforce.ibmcloud.com/vulnerabilities/119393 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Versions D.60 and lower

Remediation/Fixes

Upgrade to version E.20 or later.
After applying the fix, all passwords should either be confirmed or changed to ensure that they were not changed (and therefore accessible) by a third-party.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmts3200_tape_libraryMatchany
VendorProductVersionCPE
ibmts3200_tape_libraryanycpe:2.3:h:ibm:ts3200_tape_library:any:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

55.7%

Related for A5C6A626E4552035D145B7ABE69B9E7521D0570FDF625AEB0CDD03327112130C