CVE-2014-0875
IBM Storwize V7000 Unified 1.3.0.0-1.4.3.x - Unauthenticated ACL Bypass via NFS Retransmission
Title source: llmDescription
Active Cloud Engine (ACE) in IBM Storwize V7000 Unified 1.3.0.0 through 1.4.3.x allows remote attackers to bypass intended ACL restrictions in opportunistic circumstances by leveraging incorrect ACL synchronization over an unreliable NFS connection that requires retransmissions.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/68398
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=ssg1S1004738
Scores
EPSS
0.0125
EPSS Percentile
66.3%
Details
CWE
CWE-264
Status
published
Products (16)
ibm/storwize_unified_v7000
ibm/storwize_unified_v7000_software
1.3.0.0
ibm/storwize_unified_v7000_software
1.3.1.0
ibm/storwize_unified_v7000_software
1.4.0.0
ibm/storwize_unified_v7000_software
1.4.0.1
ibm/storwize_unified_v7000_software
1.4.0.2
ibm/storwize_unified_v7000_software
1.4.0.3
ibm/storwize_unified_v7000_software
1.4.0.4
ibm/storwize_unified_v7000_software
1.4.0.5
ibm/storwize_unified_v7000_software
1.4.1.0
... and 6 more
Published
Jul 07, 2014
Tracked Since
Feb 18, 2026