Description
IBM Storwize 3500, 3700, 5000, and 7000 devices and SAN Volume Controller 6.x and 7.x before 7.2.0.8 allow remote attackers to reset the administrator superuser password to its default value via a direct request to the administrative IP address.
References (4)
Core 4
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=ssg1S1004846
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/69771
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/61075
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/95387
Scores
EPSS
0.0274
EPSS Percentile
84.6%
Details
CWE
CWE-255
Status
published
Products (50)
ibm/san_volume_controller_software
6.1.0.0
ibm/san_volume_controller_software
6.1.0.1
ibm/san_volume_controller_software
6.1.0.2
ibm/san_volume_controller_software
6.1.0.3
ibm/san_volume_controller_software
6.1.0.4
ibm/san_volume_controller_software
6.1.0.5
ibm/san_volume_controller_software
6.1.0.6
ibm/san_volume_controller_software
6.1.0.7
ibm/san_volume_controller_software
6.1.0.8
ibm/san_volume_controller_software
6.1.0.9
... and 40 more
Published
Sep 12, 2014
Tracked Since
Feb 18, 2026