5.4
CVSSv2

CVE-2013-0500

Published: 17/10/2013 Updated: 29/08/2017
CVSS v2 Base Score: 5.4 | Impact Score: 6.4 | Exploitability Score: 5.5
VMScore: 481
Vector: AV:N/AC:M/Au:M/C:P/I:P/A:P

Vulnerability Summary

IBM Storwize V7000 Unified 1.3.x and 1.4.x prior to 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed with a non-NFS protocol, which allows remote authenticated users to obtain sensitive information, modify programs or files, or cause a denial of service (device crash) via a (1) CIFS, (2) HTTPS, (3) SCP, or (4) SFTP operation.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm storwize_v7000_unified_software 1.4.1.1

ibm storwize_v7000_unified_software 1.3.2.3

ibm storwize_v7000_unified_software 1.4.0.4

ibm storwize_v7000_unified_software 1.3.2.0

ibm storwize_v7000_unified_software 1.4.0.0

ibm storwize_v7000_unified_software 1.4.1.0

ibm storwize_v7000_unified_software 1.3.0.0

ibm storwize_v7000_unified -