CVE-2014-4811

IBM Storwize - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM Storwize 3500, 3700, 5000, and 7000 devices and SAN Volume Controller 6.x and 7.x before 7.2.0.8 allow remote attackers to reset the administrator superuser password to its default value via a direct request to the administrative IP address.

References (4)

Core 4
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=ssg1S1004846
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69771
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61075
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/95387

Scores

EPSS 0.0274
EPSS Percentile 84.6%

Details

CWE
CWE-255
Status published
Products (50)
ibm/san_volume_controller_software 6.1.0.0
ibm/san_volume_controller_software 6.1.0.1
ibm/san_volume_controller_software 6.1.0.2
ibm/san_volume_controller_software 6.1.0.3
ibm/san_volume_controller_software 6.1.0.4
ibm/san_volume_controller_software 6.1.0.5
ibm/san_volume_controller_software 6.1.0.6
ibm/san_volume_controller_software 6.1.0.7
ibm/san_volume_controller_software 6.1.0.8
ibm/san_volume_controller_software 6.1.0.9
... and 40 more
Published Sep 12, 2014
Tracked Since Feb 18, 2026