Lucene search

K
ibmIBMFDA728C1A12F4AC02D525291250B55E23BCC46CC270939D5FE20DBC06B772193
HistorySep 27, 2023 - 7:22 p.m.

Security Bulletin: Vulnerability with Certifi affect IBM Cloud Object Storage Systems (Sept2023v3)

2023-09-2719:22:57
www.ibm.com
26
certifi vulnerability
ibm cloud object storage
cve-2023-37920
e-tugra root certificate
cvss 7.5
fix 3.17.5.79

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

29.9%

Summary

Vulnerability with Certifi (CVE-2023-37920) This vulnerability have been addressed in the latest ClevOS releases

Vulnerability Details

CVEID:CVE-2023-37920
**DESCRIPTION:**An unspecified error with the removal of e-Tugra root certificate in Certifi has an unknown impact and attack vector.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/261639 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Object System 3.17.5.57 or Prior Release

Remediation/Fixes

roduct(s) Version Number Remediation/Fix
IBM Cloud Object System 3.17.5.79 https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Cloud+Object+Storage+System&release=3.17.5.79&platform=All&function=all

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_object_storage_systemMatch3.17
CPENameOperatorVersion
ibm cloud object storage systemeq3.17

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

29.9%