Lucene search

K
ibmIBMAFEF8F129D656054C0976924DD7685942E8D723327E6B0ED2E1DDB460EB5AE2E
HistoryJun 18, 2018 - 12:07 a.m.

Security Bulletin: CLI access security issue on IBM System Storage Storwize V7000 Unified (CVE-2014-0880)

2018-06-1800:07:42
www.ibm.com
7

0.005 Low

EPSS

Percentile

76.4%

Summary

CLI security issue.

Vulnerability Details

**CVEID:**CVE-2014-0880

DESCRIPTION:

An unauthorized user with network access to a system’s administrative IP (Internet Protocol) address may be able to gain access to the block CLI (Command Line Interface) of the system, allowing the user to issue all administrative commands, with the potential to disrupt normal system operation. Authentication via the GUI (Graphical User Interface) is unaffected.

CVE-2014-0880
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/91145 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

Affected Products and Versions

Affected releases: IBM Storwize V7000 Unified 1.3.0.0 through 1.4.2.1._
Releases/systems/configurations NOT affected_: IBM Storwize V7000 Unified 1.4.3.0 and above.

Remediation/Fixes

This issue was fixed beginning with version 1.4.3.0 of IBM Storwize V7000 Unified. IBM Storwize V7000 Unified customers running an earlier version must upgrade to IBM Storwize V7000 Unified 1.4.3.0 or a later version in order to get these fixes.

Workarounds and Mitigations

Ensure that all users who have access to the system are authenticated by another security system such as a firewall

0.005 Low

EPSS

Percentile

76.4%

Related for AFEF8F129D656054C0976924DD7685942E8D723327E6B0ED2E1DDB460EB5AE2E