CVE-2012-4829

IBM XIV Storage System Gen3 <11.2 - Man-in-the-middle

Title source: llm
STIX 2.1

Description

IBM XIV Storage System Gen3 before 11.2 relies on a default X.509 v3 certificate for authentication, which allows man-in-the-middle attackers to spoof servers by leveraging an inappropriate certificate-trust relationship.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78860

Scores

EPSS 0.0055
EPSS Percentile 42.6%

Details

CWE
CWE-310
Status published
Products (1)
ibm/xiv_storage_system_gen3 < 11.1
Published Apr 16, 2013
Tracked Since Feb 18, 2026