IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain user access via unknown vectors. IBM X-Force ID: 75041.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/75041 | VDB Entry Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004256 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Information
Published : 2018-02-08 15:29
Updated : 2018-03-10 07:07
NVD link : CVE-2012-2166
Mitre link : CVE-2012-2166
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
ibm
- xiv_storage_system_2812-a14_firmware
- xiv_storage_system_2812-a14
- xiv_storage_system_2810-114_firmware
- xiv_storage_system_2812-114_firmware
- xiv_storage_system_2810-a14_firmware
- xiv_storage_system_2810-114
- xiv_storage_system_2812-114
- xiv_storage_system_2810-a14