CVE-2018-1822
Summary
| CVE | CVE-2018-1822 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-18 15:29:00 UTC |
| Updated | 2019-10-09 23:39:00 UTC |
| Description | IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attacker to gain administrative control or to deny service. IBM X-Force ID: 150296. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ibm | Flashsystem 840 | All | All | All | All |
| Hardware | Ibm | Flashsystem 840 | All | All | All | All |
| Operating System | Ibm | Flashsystem 840 Firmware | 1.4 | All | All | All |
| Operating System | Ibm | Flashsystem 840 Firmware | 1.4 | All | All | All |
| Hardware | Ibm | Flashsystem 900 | All | All | All | All |
| Hardware | Ibm | Flashsystem 900 | All | All | All | All |
| Operating System | Ibm | Flashsystem 900 Firmware | 1.4 | All | All | All |
| Operating System | Ibm | Flashsystem 900 Firmware | 1.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| Security Bulletin: Vulnerability in the IBM FlashSystem models 840 and 900 | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.