CVE-2012-2166

CRITICAL

IBM XIV Storage System Hard-coded Credentials Vulnerability

Title source: llm
STIX 2.1

Description

IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain user access via unknown vectors. IBM X-Force ID: 75041.

References (2)

Core 2
Core References
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75041

Scores

CVSS v3 9.8
EPSS 0.0276
EPSS Percentile 84.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (4)
ibm/xiv_storage_system_2810-114_firmware < 11.1.1
ibm/xiv_storage_system_2810-a14_firmware < 10.2.4.e-2
ibm/xiv_storage_system_2812-114_firmware < 11.1.1
ibm/xiv_storage_system_2812-a14_firmware < 10.2.4.e-2
Published Feb 08, 2018
Tracked Since Feb 18, 2026