PT-2024-13475 · Ibm · Ibm Storage Virtualize+3

Published

2024-02-07

·

Updated

2024-02-15

·

CVE-2023-47700

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM SAN Volume Controller version 8.6 IBM Storwize version 8.6 IBM FlashSystem version 8.6 IBM Storage Virtualize version 8.6
Description The issue allows a remote attacker to spoof a trusted system that would not be correctly validated by the Storwize server. This could lead to a user connecting to a malicious host, believing that it was a trusted system and deceived into accepting spoofed data.
Recommendations For IBM SAN Volume Controller version 8.6, consider restricting access to the Storwize server until a patch is available. For IBM Storwize version 8.6, consider disabling the validation mechanism temporarily to minimize the risk of exploitation. For IBM FlashSystem version 8.6, restrict access to the system to prevent potential spoofing attacks. For IBM Storage Virtualize version 8.6, avoid using the system for trusted connections until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47700

Affected Products

Ibm Flashsystem
Ibm San Volume Controller
Ibm Storage Virtualize
Ibm Storwize