IBM XIV Storage System Gen3 before 11.2 relies on a default X.509 v3 certificate for authentication, which allows man-in-the-middle attackers to spoof servers by leveraging an inappropriate certificate-trust relationship.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004323 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/78860 |
Configurations
Information
Published : 2013-04-16 07:04
Updated : 2017-08-28 18:32
NVD link : CVE-2012-4829
Mitre link : CVE-2012-4829
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
ibm
- xiv_storage_system_gen3