PT-2024-13475 · Ibm · Ibm Storage Virtualize+3
Published
2024-02-07
·
Updated
2024-02-15
·
CVE-2023-47700
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM SAN Volume Controller version 8.6
IBM Storwize version 8.6
IBM FlashSystem version 8.6
IBM Storage Virtualize version 8.6
Description
The issue allows a remote attacker to spoof a trusted system that would not be correctly validated by the Storwize server. This could lead to a user connecting to a malicious host, believing that it was a trusted system and deceived into accepting spoofed data.
Recommendations
For IBM SAN Volume Controller version 8.6, consider restricting access to the Storwize server until a patch is available.
For IBM Storwize version 8.6, consider disabling the validation mechanism temporarily to minimize the risk of exploitation.
For IBM FlashSystem version 8.6, restrict access to the system to prevent potential spoofing attacks.
For IBM Storage Virtualize version 8.6, avoid using the system for trusted connections until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Flashsystem
Ibm San Volume Controller
Ibm Storage Virtualize
Ibm Storwize