Lucene search

K
ibmIBMB0975717E5BDE996AB16AC3ECA372A52DC903978609DFE755AC3EA662E9B7384
HistoryJun 22, 2023 - 6:34 p.m.

Security Bulletin: IBM Storage Protect Server is vulnerable to attacks due to Golang Go (CVE-2023-24532)

2023-06-2218:34:51
www.ibm.com
9
ibm storage protect server
vulnerability
golang go
cve-2023-24532
cvss
affected versions
fix
platform
ibm support

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

0.001 Low

EPSS

Percentile

39.8%

Summary

Golang Go is used by IBM Storage Protect Server and may be affected by this vulnerability.

Vulnerability Details

CVEID:CVE-2023-24532
**DESCRIPTION:**An unspecified error with return an incorrect result in the ScalarMult and ScalarBaseMult methods of the P256 Curve in Golang Go has an unknown impact and attack vector.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/249655 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Storage Protect Server 8.1

Remediation/Fixes

IBM Storage Protect Server Affected Versions Fixing Level Platform Link to Fix and Instructions
8.1.0.000 - 8.1.18.xxx 8.1.19 AIX, Linux, Windows <https://www.ibm.com/support/pages/node/6988821&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmspectrum_protectMatch8.1
CPENameOperatorVersion
ibm spectrum protecteq8.1

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

0.001 Low

EPSS

Percentile

39.8%