Lucene search

K
ibmIBMD72039A541262C5C7DD8004D30EA7974A224B2DC3E698501A93E18885B4C3EE4
HistoryJul 02, 2024 - 10:30 a.m.

Security Bulletin: Disabled USB port vulnerability affects IBM FlashSystem 5300

2024-07-0210:30:49
www.ibm.com
9
ibm flashsystem 5300
usb port
vulnerability
administrator
physical access
data loss
cve-2024-39723
cvss 4.6
ibm storage virtualize 8.6
remediation
upgrade 8.7.0.0

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0

Percentile

9.2%

Summary

IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data.

Vulnerability Details

CVEID:CVE-2024-39723
**DESCRIPTION:**IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data.
CVSS Base score: 4.6
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/295935 for the current score.
CVSS Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Storage Virtualize 8.6

Remediation/Fixes

IBM recommends that you fix this vulnerability by upgrading affected version of IBM FlashSystem 5300 to the following code levels or higher:

8.7.0.0

Latest IBM FlashSystem 5300 Code

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmibm_flashsystem_5x00Match8.6
VendorProductVersionCPE
ibmibm_flashsystem_5x008.6cpe:2.3:a:ibm:ibm_flashsystem_5x00:8.6:*:*:*:*:*:*:*

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0

Percentile

9.2%

Related for D72039A541262C5C7DD8004D30EA7974A224B2DC3E698501A93E18885B4C3EE4