9.8
CVSSv3

CVE-2018-1822

Published: 18/10/2018 Updated: 09/10/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an malicious user to gain administrative control or to deny service. IBM X-Force ID: 150296.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm flashsystem_900_firmware 1.4

ibm flashsystem_840_firmware 1.4