CVE-2014-0875
Summary
| CVE | CVE-2014-0875 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-07 11:01:29 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Active Cloud Engine (ACE) in IBM Storwize V7000 Unified 1.3.0.0 through 1.4.3.x allows remote attackers to bypass intended ACL restrictions in opportunistic circumstances by leveraging incorrect ACL synchronization over an unreliable NFS connection that requires retransmissions. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ibm | Storwize Unified V7000 | - | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.3.0.0 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.3.1.0 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.0.0 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.0.1 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.0.2 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.0.3 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.0.4 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.0.5 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.1.0 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.1.1 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.2.0 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.2.1 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.3.0 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.3.1 | All | All | All |
| Application | Ibm | Storwize Unified V7000 Software | 1.4.3.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Incorrect access control list (ACL) might occur in case of a network retransmission, when Active Cloud Engine (ACE) is being used on IBM Storwize V7000 Unified system (CVE-2014-0875) | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| IBM Storwize V7000 Unified CVE-2014-0875 Unauthorized Access Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.