CVE Vulnerabilities

CVE-2012-6354

Improper Authentication

Published: Feb 19, 2013 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain superuser access via IP packets.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
San_volume_controller_software Ibm 6.1.0.0 (including) 6.1.0.0 (including)
San_volume_controller_software Ibm 6.2.0.0 (including) 6.2.0.0 (including)
San_volume_controller_software Ibm 6.3.0.0 (including) 6.3.0.0 (including)
San_volume_controller_software Ibm 6.4.0.0 (including) 6.4.0.0 (including)
Storwize_v7000 Ibm - (including) - (including)

Potential Mitigations

References