Security bulletin: Authentication bypass vulnerability in IBM SAN Volume Controller and Storwize Family (CVE-2012-6354)

Flash (Alert)


Abstract

Administrative access to the system via the GUI may be obtained without supplying proper credentials.

Content

VULNERABILITY DETAILS

CVE ID:

CVE-2012-6354

DESCRIPTION:

The vulnerability can be exploited by a user with access to the system's management IP interface. If successful the user can gain access with superuser privilege which will allow any modification to the configuration, including complete deletion.

CVSS:
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/80716 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

AFFECTED PRODUCTS:

IBM SAN Volume Controller
IBM Storwize V7000
IBM Storwize V3500
IBM Storwize V3700
IBM Flex System V7000



REMEDIATION:

For IBM SAN Volume Controller and IBM Storwize V7000 install PTF level 7.1.0.1, 6.4.1.3, 6.3.0.7 or 6.2.0.6.

For IBM Storwize V3700 and V3500, and IBM Flex System V7000 install PTF level 7.1.0.1 or 6.4.1.3.

    Workaround(s):
    None

    Mitigation(s):
    Access to the system's IP interface can be restricted, for example using a private network or firewall technology.

REFERENCES:
· Complete CVSS Guide
· On-line Calculator V2
· CVE-2012-6354
· X-Force Vulnerability Database http://xforce.iss.net/xforce/xfdb/80716
RELATED INFORMATION:

none

ACKNOWLEDGEMENT:

Vulnerability reported by Marcin Mielnoczek of Narodowe Archiwum Cyfrowe (National Digital Archives)

Cross reference information
Segment Product Component Platform Version Edition
Storage Virtualization SAN Volume Controller 6.4 SAN Volume Controller 6.1, 6.2, 6.3, 6.4
Disk Storage Systems IBM Storwize V3500 (2071) 6.4 Platform Independent 6.4
Disk Storage Systems IBM Storwize V3700 (2072) 6.4 Platform Independent Not Applicable
Disk Storage Systems Flex System V7000 6.4 Platform Independent 6.4

Rate this page:

(0 users)Average rating

Add comments

Document information


More support for:

IBM Storwize V7000 (2076)
6.4

Version:

6.1, 6.2, 6.3, 6.4

Operating system(s):

IBM Storwize V7000

Reference #:

S1004277

Modified date:

2013-06-20

Translate my page

Machine Translation

Content navigation