5.4
CVSSv2

CVE-2013-0500

Published: 17/10/2013 Updated: 29/08/2017
CVSS v2 Base Score: 5.4 | Impact Score: 6.4 | Exploitability Score: 5.5
VMScore: 481
Vector: AV:N/AC:M/Au:M/C:P/I:P/A:P

Vulnerability Summary

IBM Storwize V7000 Unified 1.3.x and 1.4.x prior to 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed with a non-NFS protocol, which allows remote authenticated users to obtain sensitive information, modify programs or files, or cause a denial of service (device crash) via a (1) CIFS, (2) HTTPS, (3) SCP, or (4) SFTP operation.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm storwize v7000 unified software 1.3.0.0

ibm storwize v7000 unified software 1.3.2.0

ibm storwize v7000 unified software 1.3.2.3

ibm storwize v7000 unified software 1.4.0.0

ibm storwize v7000 unified software 1.4.0.4

ibm storwize v7000 unified software 1.4.1.0

ibm storwize v7000 unified software 1.4.1.1

ibm storwize v7000 unified -