IBM XIV Storage System Gen3 before 11.2 relies on a default X.509 v3 certificate for authentication, which allows man-in-the-middle attackers to spoof servers by leveraging an inappropriate certificate-trust relationship.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xiv_storage_system_gen3 | Ibm | * | 11.1 (including) |