← volver
CVE-2023-47700

IBM Storage Virtualize improper certificate validation

CVSS 5.9 MEDIUMEPSS 0.5%CWE-295
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.9EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
07 feb 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote attacker to spoof a trusted system that would not be correctly validated by the Storwize server. This could lead to a user connecting to a malicious host, believing that it was a trusted system and deceived into accepting spoofed data. IBM X-Force ID: 271016.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Productos afectados
IBM · Storage Virtualize

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →