CVE-2018-1466
5.3
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.6 / Impact: 3.6
Source: NVD
Description
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 140397.
Affected (40)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1.0.0 to 7.5.0.14 |
| Running on/with | Platform Versions |
|---|---|
Ibm Storwize V7000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1.0.0 to 7.5.0.14 |
| Running on/with | Platform Versions |
|---|---|
Ibm Storwize V5000 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1.0.0 to 7.5.0.14 |
| Running on/with | Platform Versions |
|---|---|
Ibm Storwize V3700 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1.0.0 to 7.5.0.14 |
| Running on/with | Platform Versions |
|---|---|
Ibm Storwize V3500 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1.0.0 to 7.5.0.14 |
| Running on/with | Platform Versions |
|---|---|
Ibm Storwize V9000 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1.0.0 to 7.5.0.14 |
| Running on/with | Platform Versions |
|---|---|
Ibm San Volume Controller | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1.0.0 to 7.5.0.14 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.1.0.0 to 7.5.0.14 |
References (10)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Timeline
No history available yet.