6.8
CVSSv2

CVE-2011-1372

Published: 28/11/2011 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote malicious users to bypass authentication and obtain administrative access via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm ts3200_tape_library_firmware

ibm ts3100_tape_library_firmware

ibm ts3100_tape_library

ibm ts3200_tape_library

Exploits

The IBM TS3200/TS3200 Web User Interface is vulnerable to an authentication bypass attack By sending a series of requests to the authentication function, it is possible to trigger a condition which causes the application to grant an access cookie which permits remote administration Firmware less than A60 is affected ...