CVE-2012-2166
CRITICALIBM XIV Storage System Hard-coded Credentials Vulnerability
Title source: llmDescription
IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain user access via unknown vectors. IBM X-Force ID: 75041.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004256
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75041
Scores
CVSS v3
9.8
EPSS
0.0276
EPSS Percentile
84.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-798
Status
published
Products (4)
ibm/xiv_storage_system_2810-114_firmware
< 11.1.1
ibm/xiv_storage_system_2810-a14_firmware
< 10.2.4.e-2
ibm/xiv_storage_system_2812-114_firmware
< 11.1.1
ibm/xiv_storage_system_2812-a14_firmware
< 10.2.4.e-2
Published
Feb 08, 2018
Tracked Since
Feb 18, 2026