IBM Security Proventia Network Active Bypass has addressed the following vulnerabilities. (CVE-2018-6485)
CVEID: CVE-2018-6485 DESCRIPTION: GNU C Library is vulnerable to a denial of service, caused by an integer overflow in the implementation of the posix_memalign in memalign functions. A local attacker could exploit this vulnerability to cause the application to crash.
CVSS Base Score: 4
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/138627> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
IBM Security 1G Network Active Bypass firmware version 1.x through 3.x firmware levels 1.0.849 through 3.30.10-37
IBM Security 10G Network Active Bypass firmware versions 1.x through 3.x firmware levels 1.0.1876 through 3.30.10-37
Product | VRMF | Remediation/First Fix |
---|---|---|
IBM Security Proventia Network Active Bypass | 3.X | Proventia 1G NAB Update 24 (fw 3.30.11) IBM Security Proventia Network Active Bypass |
For IBM Security Proventia Network Active Bypass products at the following firmware versions:
IBM recommends upgrading to 3.30.11, the supported firmware release of the product.
None
CPE | Name | Operator | Version |
---|---|---|---|
ibm security network active bypass | eq | 3. |