CVE Vulnerabilities

CVE-2012-6354

Improper Authentication

Published: Feb 19, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain superuser access via IP packets.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
San_volume_controller_softwareIbm6.1.0.0 (including)6.1.0.0 (including)
San_volume_controller_softwareIbm6.2.0.0 (including)6.2.0.0 (including)
San_volume_controller_softwareIbm6.3.0.0 (including)6.3.0.0 (including)
San_volume_controller_softwareIbm6.4.0.0 (including)6.4.0.0 (including)
Storwize_v7000Ibm- (including)- (including)

Potential Mitigations

References