CVE-2021-29873
CVE-2021-29873
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 1.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
21 Oct 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.
CVSS:3.0/A:H/AV:N/I:H/PR:L/C:H/S:U/UI:N/AC:L/E:U/RC:C/RL:O
Affected products
IBM · FlashSystem 900IBM · FlashSystem 9100 FamilyIBM · FlashSystem V9000IBM · SAN Volume ControllerIBM · Spectrum Virtualize for Public CloudIBM · Spectrum Virtualize SoftwareIBM · Storwize V3500IBM · Storwize V3700IBM · Storwize V5000IBM · Storwize V5100IBM · Storwize V7000Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →