Vulnerability CVE-2020-4756


Published: 2020-10-20

Description:
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service. IBM X-Force ID: 188599.

Type:

CWE-404

(Improper Resource Shutdown or Release)

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.9/10
6.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
IBM -> Elastic storage server 
IBM -> Spectrum scale 

 References:
https://exchange.xforce.ibmcloud.com/vulnerabilities/188599
https://www.ibm.com/support/pages/node/6349469
https://www.ibm.com/support/pages/node/6349475

Copyright 2024, cxsecurity.com

 

Back to Top